{"api_version":"1","generated_at":"2026-07-23T06:49:44+00:00","cve":"CVE-2016-8625","urls":{"html":"https://cve.report/CVE-2016-8625","api":"https://cve.report/api/cve/CVE-2016-8625.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8625","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8625"},"summary":{"title":"CVE-2016-8625","description":"curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-08-01 06:29:00","updated_at":"2023-11-07 02:36:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","name":"[bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8","refsource":"","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E","name":"[bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8","refsource":"MLIST","tags":[],"title":"Pony Mail!","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://access.redhat.com/errata/RHSA-2018:3558","name":"RHSA-2018:3558","refsource":"REDHAT","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://curl.haxx.se/CVE-2016-8625.patch","name":"https://curl.haxx.se/CVE-2016-8625.patch","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"https://curl.haxx.se/docs/adv_20161102K.html","name":"https://curl.haxx.se/docs/adv_20161102K.html","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"curl - IDNA 2003 makes curl use wrong","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/94107","name":"94107","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"cURL/libcURL CVE-2016-8625 Remote Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2018:2486","name":"RHSA-2018:2486","refsource":"REDHAT","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E","name":"[bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8","refsource":"MLIST","tags":[],"title":"Pony Mail!","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","name":"[bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8","refsource":"","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1037192","name":"1037192","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"cURL/libcurl Multiple Bugs Let Remote Users Inject Cookies, Reuse Connections, and Execute Arbitrary Code and Let Local Users Obtain Potentially Sensitive Information and Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201701-47","name":"GLSA-201701-47","refsource":"GENTOO","tags":["Third Party Advisory"],"title":"cURL: Multiple vulnerabilities (GLSA 201701-47) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.tenable.com/security/tns-2016-21","name":"https://www.tenable.com/security/tns-2016-21","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"[R1] LCE 4.8.2 Fixes Multiple Third-party Library Vulnerabilities - Security Advisory | Tenable Network Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625","refsource":"CONFIRM","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"1388392 – (CVE-2016-8625) CVE-2016-8625 curl: IDNA 2003 makes curl use wrong host","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8625","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8625","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8625","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"haxx","cpe5":"curl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8625","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"haxx","cpe5":"curl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2016-8625","qid":"500114","title":"Alpine Linux Security Update for curl"},{"cve":"CVE-2016-8625","qid":"503769","title":"Alpine Linux Security Update for curl"},{"cve":"CVE-2016-8625","qid":"710385","title":"Gentoo Linux cURL Multiple Vulnerabilities (GLSA 201701-47)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2016-8625","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"curl","version":{"version_data":[{"version_value":"7.51.0"}]}}]},"vendor_name":"The Curl Project"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host."}]},"impact":{"cvss":[[{"vectorString":"5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.0"}],[{"vectorString":"4.3/AV:N/AC:M/Au:N/C:N/I:P/A:N","version":"2.0"}]]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20"}]}]},"references":{"reference_data":[{"name":"94107","refsource":"BID","url":"http://www.securityfocus.com/bid/94107"},{"name":"https://curl.haxx.se/CVE-2016-8625.patch","refsource":"CONFIRM","url":"https://curl.haxx.se/CVE-2016-8625.patch"},{"name":"RHSA-2018:3558","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2018:3558"},{"name":"https://www.tenable.com/security/tns-2016-21","refsource":"CONFIRM","url":"https://www.tenable.com/security/tns-2016-21"},{"name":"https://curl.haxx.se/docs/adv_20161102K.html","refsource":"CONFIRM","url":"https://curl.haxx.se/docs/adv_20161102K.html"},{"name":"1037192","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1037192"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625"},{"name":"RHSA-2018:2486","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2018:2486"},{"name":"GLSA-201701-47","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201701-47"},{"refsource":"MLIST","name":"[bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8","url":"https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E"},{"refsource":"MLIST","name":"[bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8","url":"https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E"}]}},"nvd":{"publishedDate":"2018-08-01 06:29:00","lastModifiedDate":"2023-11-07 02:36:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*","versionEndExcluding":"7.51.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8625","Ordinal":"95280","Title":"CVE-2016-8625","CVE":"CVE-2016-8625","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8625","Ordinal":"1","NoteData":"curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"8625","Ordinal":"2","NoteData":"2018-08-01","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8625","Ordinal":"3","NoteData":"2021-06-29","Type":"Other","Title":"Modified"}]}}}