{"api_version":"1","generated_at":"2026-07-23T01:51:57+00:00","cve":"CVE-2016-8622","urls":{"html":"https://cve.report/CVE-2016-8622","api":"https://cve.report/api/cve/CVE-2016-8622.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8622","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8622"},"summary":{"title":"CVE-2016-8622","description":"The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return that new length in a signed 32 bit integer variable, thus the length would get either just truncated or both truncated and turned negative. That could then lead to libcurl writing outside of its heap based buffer.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-07-31 21:29:00","updated_at":"2023-11-07 02:36:00"},"problem_types":["CWE-787"],"metrics":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2018:3558","name":"RHSA-2018:3558","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/94105","name":"94105","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"cURL/libcURL CVE-2016-8622 Remote Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8622","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8622","refsource":"CONFIRM","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"1388386 – (CVE-2016-8622) CVE-2016-8622 curl: URL unescape heap overflow via integer truncation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2018:2486","name":"RHSA-2018:2486","refsource":"REDHAT","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://curl.haxx.se/docs/adv_20161102H.html","name":"https://curl.haxx.se/docs/adv_20161102H.html","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"curl - URL unescape heap overflow via integer truncation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","name":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","refsource":"CONFIRM","tags":[],"title":"CPU Oct 2018","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1037192","name":"1037192","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"cURL/libcurl Multiple Bugs Let Remote Users Inject Cookies, Reuse Connections, and Execute Arbitrary Code and Let Local Users Obtain Potentially Sensitive Information and Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201701-47","name":"GLSA-201701-47","refsource":"GENTOO","tags":["Third Party Advisory"],"title":"cURL: Multiple vulnerabilities (GLSA 201701-47) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.tenable.com/security/tns-2016-21","name":"https://www.tenable.com/security/tns-2016-21","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"[R1] LCE 4.8.2 Fixes Multiple Third-party Library Vulnerabilities - Security Advisory | Tenable Network Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8622","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8622","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8622","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"haxx","cpe5":"libcurl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8622","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"haxx","cpe5":"libcurl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2016-8622","qid":"500114","title":"Alpine Linux Security Update for curl"},{"cve":"CVE-2016-8622","qid":"503769","title":"Alpine Linux Security Update for curl"},{"cve":"CVE-2016-8622","qid":"710385","title":"Gentoo Linux cURL Multiple Vulnerabilities (GLSA 201701-47)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2016-8622","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"curl","version":{"version_data":[{"version_value":"7.51.0"}]}}]},"vendor_name":"The Curl Project"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return that new length in a signed 32 bit integer variable, thus the length would get either just truncated or both truncated and turned negative. That could then lead to libcurl writing outside of its heap based buffer."}]},"impact":{"cvss":[[{"vectorString":"3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.0"}],[{"vectorString":"2.6/AV:N/AC:H/Au:N/C:N/I:P/A:N","version":"2.0"}]]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-190"}]},{"description":[{"lang":"eng","value":"CWE-122"}]}]},"references":{"reference_data":[{"name":"RHSA-2018:3558","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2018:3558"},{"name":"https://curl.haxx.se/docs/adv_20161102H.html","refsource":"CONFIRM","url":"https://curl.haxx.se/docs/adv_20161102H.html"},{"name":"https://www.tenable.com/security/tns-2016-21","refsource":"CONFIRM","url":"https://www.tenable.com/security/tns-2016-21"},{"name":"1037192","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1037192"},{"name":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"},{"name":"94105","refsource":"BID","url":"http://www.securityfocus.com/bid/94105"},{"name":"RHSA-2018:2486","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2018:2486"},{"name":"GLSA-201701-47","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201701-47"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8622","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8622"}]}},"nvd":{"publishedDate":"2018-07-31 21:29:00","lastModifiedDate":"2023-11-07 02:36:00","problem_types":["CWE-787"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*","versionEndExcluding":"7.51.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8622","Ordinal":"95277","Title":"CVE-2016-8622","CVE":"CVE-2016-8622","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8622","Ordinal":"1","NoteData":"The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return that new length in a signed 32 bit integer variable, thus the length would get either just truncated or both truncated and turned negative. That could then lead to libcurl writing outside of its heap based buffer.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"8622","Ordinal":"2","NoteData":"2018-07-31","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8622","Ordinal":"3","NoteData":"2018-11-13","Type":"Other","Title":"Modified"}]}}}