curl 7.10

Status EOLSupport 2002-10 – 2004-01Latest 7.10.0Vulnerabilities 52← All curl versions
Critical 9.8 Unfixed
2018-03-12≤ 7.10.8

curl: negotiate not treated as connection-oriented (incomplete fix for CVE-2015-3148)

Critical 9.8
2020-02-21≤ 7.10.8

Critical 9.8
2018-01-24≤ 7.10.8

curl: HTTP authentication leak in redirects

Critical 9.8
2022-12-05≤ 7.10.8

curl: POST following PUT confusion

Critical 9.8
2023-03-30≤ 7.10.8

curl: TELNET option IAC injection

High 8.8
2005-02-21≤ 7.10.8

security flaw

High 7.5
2018-08-23≤ 7.10.6

High 7.5
2005-10-13≥ 7.10.6

security flaw

High 7.3 Unfixed
2025-01-01≥ 7.10.5

gzip integer overflow

High 7.3
2016-01-29≥ 7.10.7

curl: NTLM credentials not-checked for proxy connection re-use

Medium 6.8
2009-03-05≤ 7.10.8

curl: local file access via unsafe redirects

Medium 6.8
2013-07-31≤ 7.10.8

curl: Loop counter error, leading to heap-based buffer overflow when decoding certain URLs

Medium 6.5 Unfixed
2026-03-11≤ 7.10.8

wrong proxy connection reuse with credentials

Medium 6.5 Unfixed
2026-03-11≥ 7.10.6

bad reuse of HTTP Negotiate connection

Medium 6.5
2022-06-01≤ 7.10.8

curl: auth/cookie leak on redirect

Medium 6.4
2014-04-15≥ 7.10.6

curl: wrong re-use of connections in libcurl

Medium 5.9
2018-04-23≤ 7.10.8

curl: printf floating point buffer overflow

Medium 5.9
2023-05-26≤ 7.10.8

curl: siglongjmp race condition may lead to crash

Medium 5.8
2014-04-15≥ 7.10.3

curl: IP address wildcard certificate validation issue in libcurl

Medium 5.7
2022-06-01≤ 7.10.8

curl: credential leak on redirect

Medium 5.3
2016-01-29≤ 7.10.8

Medium 5.3
2018-07-31≤ 7.10.8

curl: Invalid URL parsing with '#'

Medium 5.3
2018-08-01≤ 7.10.8

curl: Double-free in krb5 code

Medium 5.3
2018-07-31≤ 7.10.8

curl: Double-free in curl_maprintf

Medium 5.3
2018-08-01≤ 7.10.8

curl: Cookie injection for other servers

Medium 5.3
2021-08-05≤ 7.10.8

curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure

Medium 5.3
2023-05-26≤ 7.10.8

curl: more POST-after-PUT confusion

Medium 5.0
2013-04-29≤ 7.10.8

curl: Cookie domain suffix match vulnerability

Medium 5.0
2014-11-18≤ 7.10.8

curl: incorrect handling of IP addresses in cookie domain

Medium 5.0
2015-04-24≥ 7.10.6

curl: re-using authenticated connection when unauthenticated

Medium 5.0
2015-04-24≥ 7.10.6

curl: Negotiate not treated as connection-oriented

Medium 5.0
2015-05-01≤ 7.10.8

curl: sensitive HTTP server headers also sent to proxies

Medium 4.3
2011-09-06≥ 7.10.6

HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST)

Medium 4.0
2014-02-02≥ 7.10.6

curl: re-use of wrong HTTP NTLM connection in libcurl

Low 3.7
2018-08-01≤ 7.10.8

curl: Case insensitive password comparison

Low 3.7
2020-12-14≤ 7.10.8

curl: FTP PASV command response can cause curl to connect to arbitrary host

Low 3.7
2021-08-05≥ 7.10.4

curl: Bad connection reuse due to flawed path name checks

Low 3.7
2022-09-23≤ 7.10.8

curl: Incorrect handling of control code characters in cookies

Low 3.3
2018-08-01≥ 7.10.7

curl: Use-after-free via shared cookies

Low 3.3
2018-07-31≤ 7.10.8

curl: Out-of-bounds write via unchecked multiplication

Low 3.1
2021-06-11≤ 7.10.8

curl: TELNET stack contents disclosure

Low 2.4
2017-04-03≤ 7.10.8

curl: --write-out out of bounds read

N/A
2009-08-14≤ 7.10.8

N/A
2010-03-19≥ 7.10.5

N/A
2010-03-19≥ 7.10.5

N/A
2011-07-07≥ 7.10.6

N/A
2015-01-15≤ 7.10.8

N/A
2016-08-10≤ 7.10.8

N/A
2016-08-10≤ 7.10.8

N/A
2017-10-06≤ 7.10.8

N/A
2021-04-01≤ 7.10.8

N/A
2023-10-18≤ 7.10.8