Known vulnerabilities in curl

Software: curl
Software CPE: cpe:2.3:o:fedoraproject:curl:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 126
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting curl curl is affected by 126 known vulnerabilities: 18 high, 61 medium, 47 low Critical High Medium Low

Vulnerabilities (126)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU135089 - Improper Validation of Certificate with Host Mismatch
CVE-2026-9547
CWE-297 Medium
No
No
8.15.0-8.fc43, 8.18.0-8.fc44 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 7 more
#VU135088 - Exposure of sensitive information to an unauthorized actor
CVE-2026-9546
CWE-200 Medium
No
No
8.18.0-9.fc44 24.06.2026 SB2026062427
SB2026081995
SB2026082542
#VU135087 - Exposure of sensitive information to an unauthorized actor
CVE-2026-9545
CWE-200 Low
No
No
8.15.0-9.fc43, 8.18.0-9.fc44 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 5 more
#VU135086 - Use After Free
CVE-2026-9080
CWE-416 Low
No
No
8.15.0-9.fc43, 8.18.0-9.fc44 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 5 more
#VU135084 - Insufficiently Protected Credentials
CVE-2026-8926
CWE-522 Low
No
No
8.15.0-8.fc43, 8.18.0-8.fc44 24.06.2026 SB2026062427
SB2026070135
SB2026072507
and 6 more
#VU135083 - Double Free
CVE-2026-8925
CWE-415 Low
No
No
8.15.0-9.fc43, 8.18.0-9.fc44 24.06.2026 SB2026062427
SB2026070135
SB2026081995
and 2 more
#VU135082 - Insertion of Sensitive Information Into Sent Data
CVE-2026-8924
CWE-201 Medium
No
No
8.15.0-8.fc43, 8.18.0-8.fc44 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 7 more
#VU135081 - Improper Certificate Validation
CVE-2026-8286
CWE-295 Medium
No
No
8.15.0-9.fc43, 8.18.0-9.fc44 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 7 more
#VU135080 - Improper Validation of Certificate with Host Mismatch
CVE-2026-12064
CWE-297 Medium
No
No
8.15.0-9.fc43, 8.18.0-9.fc44 24.06.2026 SB2026062427
SB2026071429
SB2026071466
and 5 more
#VU135077 - Authentication Bypass by Capture-replay
CVE-2026-8927
CWE-294 Low
No
No
8.15.0-9.fc43, 8.18.0-9.fc44 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 6 more
#VU135075 - Authentication Bypass by Capture-replay
CVE-2026-11856
CWE-294 Medium
No
No
8.15.0-8.fc43, 8.18.0-8.fc44 24.06.2026 SB2026062427
SB2026080303
SB2026080441
and 2 more
#VU135074 - Allocation of Resources Without Limits or Throttling
CVE-2026-11586
CWE-770 Medium
No
No
8.18.0-9.fc44 24.06.2026 SB2026062427
SB2026071429
SB2026081995
and 1 more
#VU135072 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-11352
CWE-835 Medium
No
No
8.18.0-9.fc44 24.06.2026 SB2026062427
SB2026071429
SB2026081995
and 1 more
#VU128459 - Authentication Bypass by Capture-replay
CVE-2026-7168
CWE-294 Medium
No
No
8.15.0-8.fc43, 8.18.0-8.fc44 29.04.2026 SB2026042955
SB2026050481
SB2026052287
and 11 more
#VU128458 - Improper Certificate Validation
CVE-2026-7009
CWE-295 Medium
No
No
8.18.0-8.fc44 29.04.2026 SB2026042955
SB2026080303
SB2026081994
#VU123889 - Authentication Bypass by Primary Weakness
CVE-2026-3784
CWE-305 Medium
No
No
8.11.1-8.fc42, 8.15.0-6.fc43, 8.18.0-6.fc44 11.03.2026 SB2026031143
SB2026031238
SB2026031262
and 18 more
#VU123888 - Authentication Bypass by Primary Weakness
CVE-2026-1965
CWE-305 Medium
No
No
8.11.1-8.fc42, 8.15.0-6.fc43, 8.18.0-6.fc44 11.03.2026 SB2026031143
SB2026031238
SB2026031262
and 13 more
#VU123887 - Use After Free
CVE-2026-3805
CWE-416 Medium
No
No
8.11.1-8.fc42, 8.15.0-6.fc43, 8.18.0-6.fc44 11.03.2026 SB2026031143
SB2026031238
SB2026031262
and 7 more
#VU123886 - Insufficiently Protected Credentials
CVE-2026-3783
CWE-522 Medium
No
No
8.11.1-8.fc42, 8.15.0-6.fc43, 8.18.0-6.fc44 11.03.2026 SB2026031143
SB2026031238
SB2026031262
and 18 more
#VU115137 - Use of Insufficiently Random Values
CVE-2025-10148
CWE-330 Low
No
No
8.11.1-6.fc42 10.09.2025 SB2025091034
SB2025091144
SB2025091301
and 10 more


Showing elements 1 - 20 out of 126