Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.6) | 0.37% | — | Wcurl | 25/2/2026 | 17/6/2026 | URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool. | |
| Aplazada | Media (5.4) | 0.27% | — | Qodeinteractive CurlyAI | 22/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Curly curly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Curly: from n/a through <= 3.3. | |
| Modificada | Baja (3.1) | 0.48% | — | Haxx Curl | 8/1/2026 | 15/9/2026 | When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent. | |
| Modificada | Media (5.3) | 0.55% | — | Haxx Curl | 8/1/2026 | 15/9/2026 | When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file. | |
| Modificada | Media (5.3) | 0.76% | — | Haxx Curl | 8/1/2026 | 15/9/2026 | When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept… | |
| Modificada | Media (5.3) | 0.68% | — | Haxx Curl | 8/1/2026 | 15/9/2026 | When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host. | |
| Modificada | Media (6.3) | 0.11% | — | Haxx Curl | 8/1/2026 | 15/9/2026 | When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature… | |
| Modificada | Media (5.9) | 0.24% | — | Haxx Curl | 8/1/2026 | 15/9/2026 | When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool, curl should check the public key of the server certificate to verify the peer. This check was skipped in a certain condition that would then make curl allow the connection without performing the proper check, thus not… | |
| Modificada | Alta (8.1) | 0.48% | — | Qodeinteractive Curly | 8/1/2026 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly curly allows PHP Local File Inclusion.This issue affects Curly: from n/a through < 3.3. | |
| Modificada | Media (4.3) | 0.40% | — | Haxx Curl | 7/11/2025 | 15/9/2026 | curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more. | |
| Modificada | Alta (7.5) | 1.4% | — | Haxx CurlDebian Linux | 12/9/2025 | 14/9/2026 | 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with only a slash as path (`path="/"`). Since this site is not secure,… | |
| Modificada | Media (5.3) | 0.50% | — | Haxx Curl | 12/9/2025 | 15/9/2026 | curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties… | |
| Analizada | Alta (7.5) | 1.4% | — | Haxx Curl | 7/6/2025 | 17/6/2026 | Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless busy-loop. There is no other way for the application to escape or exit this loop other than killing the thread/process. This might be used to DoS libcurl-using… | |
| Analizada | Media (4.8) | 0.29% | 💥 PoC | Haxx Curl | 28/5/2025 | 17/6/2026 | libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the TLS backend is wolfSSL. Documentation says the option works with wolfSSL, failing to specify that it does not for QUIC and HTTP/3. Since… | |
| Analizada | Media (6.5) | 0.29% | — | Haxx Curl | 28/5/2025 | 17/6/2026 | libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks. | |
| Analizada | Alta (7.3) | 1.3% | — | Netapp HCI Baseboard Management ControllerNetapp HCI H610s FirmwareNetapp HCI H610c FirmwareNetapp HCI H615c Firmware+4 | 5/2/2025 | 17/6/2026 | When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow. | |
| Modificada | Alta (7) | 1.3% | — | Haxx CurlNetapp Bootstrap OSNetapp H300s FirmwareNetapp H410c Firmware+3 | 5/2/2025 | 17/6/2026 | libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve. | |
| Analizada | Baja (3.4) | 0.69% | — | Haxx CurlNetapp H700s FirmwareNetapp H615c FirmwareNetapp H610s Firmware+12 | 5/2/2025 | 17/6/2026 | When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance. | |
| Modificada | Baja (3.4) | 1.3% | — | Haxx CurlNetapp OntapNetapp Ontap Select Deploy Administration UtilityNetapp H610c Firmware+7 | 11/12/2024 | 17/6/2026 | When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either… | |
| Modificada | Media (6.5) | 2.0% | — | Haxx Curl | 6/11/2024 | 17/6/2026 | When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise intended. This affects curl using applications that enable HSTS and use URLs with the insecure `HTTP://` scheme and perform transfers with hosts like… | |
| Analizada | Media (6.5) | 0.73% | — | Haxx CurlDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+6 | 11/9/2024 | 17/6/2026 | When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for… | |
| Modificada | Media (5.9) | 0.19% | — | Google Nest Mini FirmwareHaxx Libcurl | 19/8/2024 | 17/6/2026 | The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through. | |
| Modificada | Media (6.5) | 17% | — | Haxx Libcurl | 31/7/2024 | 17/6/2026 | libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not… | |
| Modificada | Media (4.3) | 0.79% | — | Haxx Libcurl | 24/7/2024 | 17/6/2026 | libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN. Asking to convert a name that is exactly 256 bytes, libcurl ends up reading outside of a stack based buffer when built to use the *macidn* IDN backend. The conversion function then… | |
| Modificada | Alta (7.5) | 4.3% | — | Haxx Libcurl | 24/7/2024 | 17/6/2026 | libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however… |