LIVE · cybersecurity feed
Live wire
vendor

Haxx

19 CVEs published in the last four months. Exploited flaws first.

Critical8
High11
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-90799.8criticalcurllibcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving 65d ago
CVE-2026-89259.8criticalcurlThe curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clear65d ago
CVE-2026-105369.8criticalcurlA use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree v65d ago
CVE-2026-118569.8criticalcurlSuccessfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and65d ago
CVE-2026-89279.1criticalcurlWhen reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl 65d ago
CVE-2026-89249.1criticalcurlA flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public 65d ago
CVE-2026-89269.1criticalcurlWhen asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(w65d ago
CVE-2026-115649.1criticalcurllibcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them ma65d ago
CVE-2026-82868.1highcurlA vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing li65d ago
CVE-2026-57737.5highcurllibcurl might in some circumstances reuse the wrong connection for SMB(S) transfers.115d ago
CVE-2026-62767.5highcurlUsing libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently d115d ago
CVE-2026-113527.5highcurlAn issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of servic65d ago
CVE-2026-115867.5highcurlBy default, curl automatically responds to WebSocket PING frames.65d ago
CVE-2026-120647.5highcurlWhen a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs65d ago
CVE-2026-89327.5highcurllibcurl would reuse a previously created connection even when some mTLS config related option had been changed that65d ago
CVE-2026-95457.5highcurlIn this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second t65d ago
CVE-2026-95467.5highcurlA vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared.65d ago
CVE-2026-95477.4highcurlWhen a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNC65d ago
CVE-2026-90807.3highcurlCalling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vul65d ago

Filter the full tracker by Haxx