| curl: libcurl: Information disclosure via improper Public Suffix List boundary check CVE-2026-82209 | Severity high |
| curl: libcurl: Improper certificate validation when using wolfSSL CA cache CVE-2026-82208 | Severity high |
| curl: curl: Information disclosure due to secure cookie attribute bypass CVE-2026-80255 | Severity high |
| curl: curl: Incorrect HTTPS connection reuse with Native CA Store CVE-2026-80231 | Severity high |
| curl: curl: Public key pinning bypass allows unauthenticated connections CVE-2026-80230 | Severity high |
| When performing transfers via libcurl’s multi interface, pooled TLS
connections can outlive their originating easy handles. In OpenSSL 3… CVE-2026-80229 | Severity high |
| curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication CVE-2026-19931 | Severity critical |
| curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections CVE-2026-18924 | Severity critical |
| curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack CVE-2026-13608 | Severity high |
| curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP CVE-2026-12064 | Severity high |
| curl: curl: Information disclosure via incorrect Digest authentication header reuse CVE-2026-11856 | Severity critical |
| curl: curl: Denial of Service via WebSocket PING flood CVE-2026-11586 | Severity high |
| libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse CVE-2026-11564 | Severity critical |
| curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability CVE-2026-11352 | Severity high |
| libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service CVE-2026-10536 | Severity critical |
| curl: curl: Man-in-the-middle attack via SSH host key bypass CVE-2026-9547 | Severity high |
| libcurl: libcurl: Information disclosure due to persistent Referer header CVE-2026-9546 | Severity high |
| libcurl: libcurl: Information disclosure via cached SSL session and early data CVE-2026-9545 | Severity high |
| libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback CVE-2026-9080 | Severity high |
| libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials CVE-2026-9079 | Severity critical |
| libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse CVE-2026-8932 | Severity high |
| curl: Information disclosure due to uncleared proxy authentication state CVE-2026-8927 | Severity critical |
| curl: curl: Information disclosure via incorrect .netrc password lookup CVE-2026-8926 | Severity critical |
| curl: curl: Double-free vulnerability in SASL authentication CVE-2026-8925 | Severity critical |
| curl: curl: Cookie injection via malicious HTTP server using super cookies CVE-2026-8924 | Severity critical |
| curl: libcurl: Unauthorized connection reuse due to a logical error CVE-2026-8458 | Severity high |
| curl: curl: Insecure connection establishment due to TLS configuration mismatch CVE-2026-8286 | Severity high |
| curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse CVE-2026-7168 | Severity medium |
| curl: libcurl: Credential leak via reused proxy connection during HTTP redirects CVE-2026-6429 | Severity medium |
| curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers CVE-2026-6276 | Severity high |
| curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies CVE-2026-6253 | Severity medium |
| curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse CVE-2026-5773 | Severity high |
| curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse CVE-2026-5545 | Severity medium |
| curl: curl: Information disclosure due to incorrect TLS connection reuse CVE-2026-4873 | Severity medium |
| curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling CVE-2026-3805 | Severity high |
| curl: curl: Unauthorized access due to improper HTTP proxy connection reuse CVE-2026-3784 | Severity medium |
| curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect CVE-2026-3783 | Severity medium |
| curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication CVE-2026-1965 | Severity medium |
| curl: libssh key passphrase bypass without agent set CVE-2025-15224 | Severity low |
| curl: Host verification bypass during SSH transfers CVE-2025-15079 | Severity medium |
| curl: libcurl: Improper certificate validation due to cached TLS settings reuse CVE-2025-14819 | Severity medium |
| curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token CVE-2025-14524 | Severity medium |
| curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers CVE-2025-14017 | Severity medium |
| curl: Public key pinning bypass via QUIC and GnuTLS allows server impersonation CVE-2025-13034 | Severity medium |
| curl: Curl missing SFTP host verification with wolfSSH backend CVE-2025-10966 | Severity medium |
| curl: predictable WebSocket mask CVE-2025-10148 | Severity medium |
| curl: libcurl: Curl out of bounds read for cookie path CVE-2025-9086 | Severity high |