Known vulnerabilities in curl

Vendor: SUSE
Software: curl
Software CPE: cpe:2.3:o:suse:curl:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 90
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting curl curl is affected by 90 known vulnerabilities: 2 high, 51 medium, 36 low Critical High Medium Low

Vulnerabilities (90)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU135089 - Improper Validation of Certificate with Host Mismatch
CVE-2026-9547
CWE-297 Medium
No
No
8.0.1-11.126.1, 8.14.1-150400.5.86.1, 8.14.1-150600.4.46.1, 8.14.1-150700.7.20.1 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 7 more
#VU135087 - Exposure of sensitive information to an unauthorized actor
CVE-2026-9545
CWE-200 Low
No
No
8.14.1-150400.5.86.1, 8.14.1-150600.4.46.1, 8.14.1-150700.7.20.1 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 4 more
#VU135086 - Use After Free
CVE-2026-9080
CWE-416 Low
No
No
8.14.1-150400.5.86.1, 8.14.1-150600.4.46.1, 8.14.1-150700.7.20.1 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 4 more
#VU135085 - Insufficiently Protected Credentials
CVE-2026-9079
CWE-522 Low
No
No
8.14.1-150400.5.86.1, 8.14.1-150600.4.46.1, 8.14.1-150700.7.20.1 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 3 more
#VU135084 - Insufficiently Protected Credentials
CVE-2026-8926
CWE-522 Low
No
No
8.14.1-150700.7.23.1 24.06.2026 SB2026062427
SB2026070135
SB2026072507
and 6 more
#VU135082 - Insertion of Sensitive Information Into Sent Data
CVE-2026-8924
CWE-201 Medium
No
No
8.0.1-11.126.1, 8.14.1-150400.5.86.1, 8.14.1-150600.4.46.1, 8.14.1-150700.7.20.1 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 7 more
#VU135081 - Improper Certificate Validation
CVE-2026-8286
CWE-295 Medium
No
No
8.0.1-11.126.1, 8.14.1-150400.5.86.1, 8.14.1-150600.4.46.1, 8.14.1-150700.7.20.1 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 6 more
#VU135080 - Improper Validation of Certificate with Host Mismatch
CVE-2026-12064
CWE-297 Medium
No
No
8.14.1-150400.5.86.1, 8.14.1-150600.4.46.1, 8.14.1-150700.7.20.1 24.06.2026 SB2026062427
SB2026071429
SB2026071466
and 4 more
#VU135077 - Authentication Bypass by Capture-replay
CVE-2026-8927
CWE-294 Low
No
No
8.14.1-150400.5.86.1, 8.14.1-150600.4.46.1, 8.14.1-150700.7.20.1 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 5 more
#VU135076 - Exposure of Data Element to Wrong Session
CVE-2026-8458
CWE-488 Low
No
No
8.0.1-11.126.1, 8.14.1-150400.5.86.1, 8.14.1-150600.4.46.1, 8.14.1-150700.7.20.1 24.06.2026 SB2026062427
SB2026070135
SB2026071466
and 4 more
#VU135070 - Use After Free
CVE-2026-10536
CWE-416 Low
No
No
8.0.1-11.126.1, 8.14.1-150400.5.86.1, 8.14.1-150600.4.46.1, 8.14.1-150700.7.20.1 24.06.2026 SB2026062427
SB2026071429
SB2026071466
and 4 more
#VU128460 - Authentication Bypass by Primary Weakness
CVE-2026-5545
CWE-305 Medium
No
No
8.0.1-11.123.1, 8.14.1-150400.5.83.1, 8.14.1-150600.4.43.1, 8.14.1-150700.7.23.1 29.04.2026 SB2026042955
SB2026050481
SB2026050706
and 11 more
#VU128459 - Authentication Bypass by Capture-replay
CVE-2026-7168
CWE-294 Medium
No
No
8.0.1-11.126.1, 8.14.1-150700.7.23.1 29.04.2026 SB2026042955
SB2026050481
SB2026052287
and 11 more
#VU128456 - Exposure of sensitive information to an unauthorized actor
CVE-2026-6429
CWE-200 Medium
No
No
8.0.1-11.123.1, 8.14.1-150400.5.83.1, 8.14.1-150600.4.43.1, 8.14.1-150700.7.23.1 29.04.2026 SB2026042955
SB2026050481
SB2026050706
and 10 more
#VU128455 - Origin Validation Error
CVE-2026-6276
CWE-346 Medium
No
No
8.0.1-11.123.1, 8.14.1-150400.5.83.1, 8.14.1-150600.4.43.1, 8.14.1-150700.7.23.1 29.04.2026 SB2026042955
SB2026050481
SB2026050706
and 10 more
#VU128454 - Insufficiently Protected Credentials
CVE-2026-6253
CWE-522 Medium
No
No
8.0.1-11.123.1, 8.14.1-150400.5.83.1, 8.14.1-150600.4.43.1, 8.14.1-150700.7.23.1 29.04.2026 SB2026042955
SB2026050481
SB2026050706
and 10 more
#VU128451 - Exposure of Data Element to Wrong Session
CVE-2026-5773
CWE-488 Medium
No
No
8.0.1-11.123.1, 8.14.1-150700.7.23.1 29.04.2026 SB2026042955
SB2026050481
SB2026052032
and 9 more
#VU128445 - Cleartext Transmission of Sensitive Information
CVE-2026-4873
CWE-319 Medium
No
No
8.0.1-11.123.1, 8.14.1-150400.5.83.1, 8.14.1-150600.4.43.1, 8.14.1-150700.7.20.1 29.04.2026 SB2026042955
SB2026050481
SB2026050706
and 10 more
#VU123888 - Authentication Bypass by Primary Weakness
CVE-2026-1965
CWE-305 Medium
No
No
8.0.1-11.120.1, 8.14.1-150200.4.103.1, 8.14.1-150400.5.80.1, 8.14.1-150400.5.83.1, 8.14.1-150600.4.40.1, 8.14.1-150600.4.43.1, 8.14.1-150700.7.14.1 11.03.2026 SB2026031143
SB2026031238
SB2026031262
and 13 more
#VU123886 - Insufficiently Protected Credentials
CVE-2026-3783
CWE-522 Medium
No
No
8.0.1-11.120.1, 8.14.1-150200.4.103.1, 8.14.1-150400.5.80.1, 8.14.1-150600.4.40.1, 8.14.1-150700.7.14.1 11.03.2026 SB2026031143
SB2026031238
SB2026031262
and 18 more


Showing elements 1 - 20 out of 90