Direct Vulnerabilities

Known vulnerabilities in the curl package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Improper Certificate Validation

<0:8.12.1-4.el10_2.3
  • M
Information Exposure

<0:8.12.1-4.el10_2.3
  • M
Authentication Bypass by Primary Weakness

<0:8.12.1-4.el10_2.3
  • M
Incorrect Implementation of Authentication Algorithm

<0:8.12.1-4.el10_2.3
  • H
Improper Verification of Cryptographic Signature

<0:8.12.1-4.el10_2.3
  • H
Improperly Implemented Security Check for Standard

<0:8.12.1-4.el10_2.3
  • H
Information Exposure

<0:8.12.1-4.el10_2.4
  • H
Improper Certificate Validation

<0:8.12.1-4.el10_2.3
  • H
Authentication Bypass by Primary Weakness

*
  • H
Authentication Bypass by Primary Weakness

<0:8.21.0-0.1.hum1
  • M
Improper Certificate Validation

<0:8.21.0-0.1.1.hum1
  • M
Comparison Using Wrong Factors

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

<0:8.21.0-0.1.1.hum1
  • M
Improper Cross-boundary Removal of Sensitive Data

*
  • H
Information Exposure

*
  • M
HTTP Request Smuggling

<0:8.21.0-0.1.1.hum1
  • M
Improper Certificate Validation

<0:8.21.0-0.1.hum1
  • M
Information Exposure

<0:8.21.0-0.1.hum1
  • M
Information Exposure

*
  • H
Improperly Implemented Security Check for Standard

<0:8.21.0-0.1.hum1
  • H
Improperly Implemented Security Check for Standard

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:8.21.0-0.1.hum1
  • M
Reliance on Cookies without Validation and Integrity Checking

<0:8.21.0-0.1.hum1
  • M
Reliance on Cookies without Validation and Integrity Checking

*
  • M
Information Exposure

<0:8.21.0-0.1.hum1
  • M
Improper Cross-boundary Removal of Sensitive Data

<0:8.21.0-0.1.hum1
  • H
Information Exposure

<0:8.21.0-0.1.hum1
  • H
Allocation of Resources Without Limits or Throttling

<0:8.21.0-0.1.hum1
  • H
Improper Certificate Validation

<0:8.21.0-0.1.hum1
  • M
Comparison Using Wrong Factors

<0:8.21.0-0.1.hum1
  • H
Improper Certificate Validation

*
  • M
Expired Pointer Dereference

<0:8.21.0-0.1.hum1
  • H
CVE-2026-8925

<0:8.21.0-0.1.hum1
  • M
Authentication Bypass

<0:8.21.0-0.1.hum1
  • M
Authentication Bypass

*
  • H
Improper Verification of Cryptographic Signature

<0:8.21.0-0.1.hum1
  • H
Improper Verification of Cryptographic Signature

*
  • M
Improper Certificate Validation

<0:8.20.0-2.hum1
  • M
Information Exposure

*
  • M
Information Exposure

<0:8.20.0-2.hum1
  • L
Origin Validation Error

*
  • L
Origin Validation Error

<0:8.20.0-0.1.hum1
  • L
Origin Validation Error

*
  • M
Cleartext Transmission of Sensitive Information

*
  • M
Cleartext Transmission of Sensitive Information

<0:8.20.0-0.1.hum1
  • M
Cleartext Transmission of Sensitive Information

*
  • M
Comparison Using Wrong Factors

*
  • M
Comparison Using Wrong Factors

<0:8.20.0-0.1.hum1
  • M
Comparison Using Wrong Factors

*
  • M
Information Exposure

*
  • M
Information Exposure

<0:8.20.0-0.1.hum1
  • M
Information Exposure

*
  • M
Exposure of Data Element to Wrong Session

*
  • M
Exposure of Data Element to Wrong Session

<0:8.20.0-0.1.hum1
  • M
Information Exposure

*
  • M
Information Exposure

<0:8.20.0-0.1.hum1
  • M
Exposure of Data Element to Wrong Session

*
  • M
Information Exposure

*
  • L
Improper Certificate Validation

<0:8.19.0-3.hum1
  • L
Information Exposure

<0:8.19.0-3.hum1
  • L
Predictability Problems

<0:8.19.0-3.hum1
  • L
Authentication Bypass by Primary Weakness

<0:8.19.0-3.hum1
  • L
Improperly Implemented Security Check for Standard

<0:8.19.0-3.hum1
  • M
Improper Certificate Validation

<0:8.19.0-3.hum1
  • M
Key Exchange without Entity Authentication

<0:8.19.0-3.hum1
  • M
Out-of-bounds Read

<0:8.19.0-3.hum1
  • L
Information Exposure

*
  • L
Information Exposure

*
  • L
Improperly Implemented Security Check for Standard

*
  • L
Improperly Implemented Security Check for Standard

*
  • L
Improper Certificate Validation

*
  • L
Improper Certificate Validation

*
  • M
Improper Certificate Validation

*
  • M
Improper Certificate Validation

*
  • L
Authentication Bypass by Primary Weakness

*
  • L
Authentication Bypass by Primary Weakness

*
  • M
Authentication Bypass by Primary Weakness

<0:8.19.0-3.hum1
  • M
Incorrect Implementation of Authentication Algorithm

<0:8.19.0-3.hum1
  • M
Expired Pointer Dereference

<0:8.19.0-3.hum1
  • M
Information Exposure

<0:8.19.0-3.hum1
  • M
Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element

<0:8.19.0-3.hum1
  • M
Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • M
Expired Pointer Dereference

*
  • M
Authentication Bypass by Primary Weakness

*
  • M
Information Exposure

*
  • M
Authentication Bypass by Primary Weakness

*
  • M
Information Exposure

*
  • M
Out-of-bounds Read

<0:8.12.1-2.el10_1.2
  • M
Out-of-bounds Read

<0:8.12.1-1.el10_0.4
  • M
Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element

*
  • M
Out-of-bounds Read

*
  • L
Predictability Problems

*
  • L
Predictability Problems

*
  • L
Out-of-bounds Read

*
  • L
Information Exposure

*
  • L
Use of Uninitialized Resource

*
  • L
Use of Uninitialized Resource

*
  • L
Untrusted Pointer Dereference

*
  • L
Improper Certificate Validation

*
  • L
Improper Authentication

*
  • M
Information Exposure

*
  • M
Use After Free

*
  • M
Improper Certificate Validation

*
  • M
Improper Input Validation

*
  • M
Out-of-bounds Write

*
  • L
Use After Free

*
  • M
Use After Free

*
  • M
Improper Input Validation

*
  • M
Use After Free

*
  • L
Improper Certificate Validation

*
  • L
Out-of-bounds Read

*
  • L
Improper Certificate Validation

*
  • L
Integer Overflow or Wraparound

*
  • L
Improper Authentication

*
  • M
Improper Certificate Validation

*
  • M
Resource Injection

*
  • M
Heap-based Buffer Overflow

*
  • M
Out-of-bounds Write

*
  • L
NULL Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • M
Improper Certificate Validation

*
  • M
Information Exposure

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Out-of-bounds Read

*
  • M
Insufficiently Protected Credentials

*
  • L
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • M
Improper Input Validation

*
  • L
Authentication Bypass

*
  • M
Improper Certificate Validation

*
  • M
Cleartext Transmission of Sensitive Information

*
  • M
Cleartext Transmission of Sensitive Information

*
  • M
Information Exposure

*
  • M
Improper Authentication

*
  • M
Improper Authentication

*
  • M
Arbitrary Code Injection

*
  • M
Information Exposure

*