Known Vulnerabilities for Libcurl by Curl
Listed below are 4 of the newest known vulnerabilities associated with "Libcurl" by "Curl".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82209 json | When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie`... | Not Provided | 2026-09-06 | 2026-09-06 |
| CVE-2026-82208 json | With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, lib... | Not Provided | 2026-09-06 | 2026-09-06 |
| CVE-2026-80231 json | A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different ... | Not Provided | 2026-09-06 | 2026-09-06 |
| CVE-2026-80230 json | When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPE... | Not Provided | 2026-09-06 | 2026-09-06 |
| CVE-2026-80229 json | When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles.... | Not Provided | 2026-09-06 | 2026-09-06 |
| CVE-2026-69246 json | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supp... | Not Provided | 2026-08-03 | 2026-08-04 |
| CVE-2026-69245 json | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a coo... | Not Provided | 2026-08-03 | 2026-08-04 |
| CVE-2026-55568 json | Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS ... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-53951 json | Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's pref... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-49129 json | Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin wher... | Not Provided | 2026-05-28 | 2026-07-14 |