curl 7.38

Status EOLSupport 2014-09 – 2014-11Latest 7.38.0Vulnerabilities 91← All curl versions
Critical 9.8
2020-02-21≤ 7.38.0

Critical 9.8
2018-03-12≤ 7.38.0

Critical 9.8
2017-11-29≤ 7.38.0

curl: NTLM buffer overflow via integer overflow

Critical 9.8
2017-11-29≤ 7.38.0

curl: FTP wildcard out of bounds read

Critical 9.8
2018-01-24≤ 7.38.0

curl: HTTP authentication leak in redirects

Critical 9.8
2018-03-14≤ 7.38.0

curl: FTP path trickery leads to NIL byte out of bounds write

Critical 9.8
2019-02-06≤ 7.38.0

curl: NTLMv2 type-3 header stack buffer overflow

Critical 9.8
2019-09-16≤ 7.38.0

curl: heap buffer overflow in function tftp_receive_packet()

Critical 9.8
2022-12-05≤ 7.38.0

curl: POST following PUT confusion

Critical 9.8
2023-03-30≤ 7.38.0

curl: TELNET option IAC injection

Critical 9.1
2018-03-14≤ 7.38.0

curl: RTSP RTP buffer over-read

Critical 9.1
2018-05-24≤ 7.38.0

curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial of service

Critical 9.0
2015-04-24≤ 7.38.0

curl: host name out of boundary memory access

High 8.8
2023-03-30≤ 7.38.0

curl: SFTP path ~ resolving discrepancy

High 8.1
2018-03-12≤ 7.38.0

High 8.1
2022-05-26≤ 7.38.0

curl: OAUTH2 bearer bypass in connection re-use

High 7.8
2016-06-24≤ 7.38.0

High 7.8
2019-05-28≤ 7.38.0

curl: TFTP receive heap buffer overflow in tftp_receive_packet() function

High 7.8
2020-12-14≤ 7.38.0

curl: Incorrect argument check can allow remote servers to overwrite local files

High 7.5
2015-04-24≤ 7.38.0

curl: cookie parser out of boundary memory access

High 7.5
2018-03-14≤ 7.38.0

curl: LDAP NULL pointer dereference

High 7.5
2021-09-29≤ 7.38.0

curl: Requirement to use TLS not properly enforced for IMAP, POP3, and FTP protocols

High 7.5
2022-06-01≤ 7.38.0

curl: CERTINFO never-ending busy-loop

High 7.5
2022-06-01≤ 7.38.0

curl: TLS and SSH connection too eager reuse

High 7.3
2025-01-01≤ 7.38.0

gzip integer overflow

High 7.3
2016-01-29≤ 7.38.0

curl: NTLM credentials not-checked for proxy connection re-use

Medium 6.5 Unfixed
2026-03-11≤ 7.38.0

wrong proxy connection reuse with credentials

Medium 6.5 Unfixed
2026-03-11≤ 7.38.0

bad reuse of HTTP Negotiate connection

Medium 6.5
2018-08-01≤ 7.38.0

curl: Glob parser write/read out of bounds

Medium 6.5
2017-10-04≤ 7.38.0

curl: URL globbing out of bounds read

Medium 6.5
2021-08-05≤ 7.38.0

curl: Content not matching hash in Metalink is not being discarded

Medium 6.5
2022-06-01≤ 7.38.0

curl: auth/cookie leak on redirect

Medium 6.3 Unfixed
2026-01-08≤ 7.38.0

broken TLS options for threaded LDAPS

Medium 5.9
2018-04-23≤ 7.38.0

curl: printf floating point buffer overflow

Medium 5.9
2021-09-29≤ 7.38.0

curl: Server responses received before STARTTLS processed after TLS handshake

Medium 5.9
2022-07-07≤ 7.38.0

curl: FTP-KRB bad message verification

Medium 5.9
2023-02-09≤ 7.38.0

curl: Use-after-free triggered by an HTTP proxy deny response

Medium 5.9
2023-05-26≤ 7.38.0

curl: siglongjmp race condition may lead to crash

Medium 5.9
2023-05-26≤ 7.38.0

curl: IDN wildcard match may lead to Improper Cerificate Validation

Medium 5.7
2022-06-01≤ 7.38.0

curl: credential leak on redirect

Medium 5.3 Unfixed
2026-04-29≤ 7.38.0

curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies

Medium 5.3 Unfixed
2026-04-29≤ 7.38.0

curl: curl: Information disclosure due to incorrect TLS connection reuse

Medium 5.3 Unfixed
2026-03-11≤ 7.38.0

token leak with redirect and netrc

Medium 5.3 Unfixed
2026-01-08≤ 7.38.0

bearer token leak on cross-protocol redirect

Medium 5.3
2016-01-29≤ 7.38.0

Medium 5.3
2016-05-20≤ 7.38.0

curl: TLS certificate name check bypass with mbedTLS and PolarSSL

Medium 5.3
2018-08-01≤ 7.38.0

curl: IDNA 2003 makes curl use wrong host

Medium 5.3
2018-07-31≤ 7.38.0

curl: Invalid URL parsing with '#'

Medium 5.3
2018-07-31≤ 7.38.0

curl: curl_getdate out-of-bounds read

Medium 5.3
2018-08-01≤ 7.38.0

curl: Double-free in krb5 code

Medium 5.3
2018-07-31≤ 7.38.0

curl: Double-free in curl_maprintf

Medium 5.3
2018-08-01≤ 7.38.0

curl: Cookie injection for other servers

Medium 5.3
2021-08-05≤ 7.38.0

curl: Metalink download sends credentials

Medium 5.3
2021-08-05≤ 7.38.0

curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure

Medium 5.3
2023-05-26≤ 7.38.0

curl: more POST-after-PUT confusion

Medium 5.0
2015-04-24≤ 7.38.0

curl: re-using authenticated connection when unauthenticated

Medium 5.0
2015-04-24≤ 7.38.0

curl: Negotiate not treated as connection-oriented

Medium 5.0
2015-05-01≤ 7.38.0

curl: sensitive HTTP server headers also sent to proxies

Medium 4.4
2018-10-31≤ 7.38.0

curl: Heap-based buffer over-read in the curl tool warning formatting

Medium 4.3
2018-10-31≤ 7.38.0

curl: Integer overflow leading to heap-based buffer overflow in Curl_sasl_create_plain_message()

Low 3.7
2018-08-01≤ 7.38.0

curl: Case insensitive password comparison

Low 3.7
2020-12-14≤ 7.38.0

curl: FTP PASV command response can cause curl to connect to arbitrary host

Low 3.7
2021-08-05≤ 7.38.0

curl: Bad connection reuse due to flawed path name checks

Low 3.7
2022-09-23≤ 7.38.0

curl: Incorrect handling of control code characters in cookies

Low 3.3
2018-08-01≤ 7.38.0

curl: Use-after-free via shared cookies

Low 3.3
2018-07-31≤ 7.38.0

curl: Out-of-bounds write via unchecked multiplication

Low 3.1
2021-06-11≤ 7.38.0

curl: TELNET stack contents disclosure

Low 2.4
2017-04-03≤ 7.38.0

curl: --write-out out of bounds read

N/A
2014-11-15≤ 7.38.0

N/A
2015-01-15≤ 7.38.0

N/A
2015-01-15≤ 7.38.0

N/A
2016-08-10≤ 7.38.0

N/A
2016-08-10≤ 7.38.0

N/A
2016-08-10≤ 7.38.0

N/A
2016-10-03≤ 7.38.0

N/A
2016-10-07≤ 7.38.0

N/A
2018-07-31≤ 7.38.0

N/A
2017-10-04≤ 7.38.0

N/A
2017-10-06≤ 7.38.0

N/A
2017-10-31≤ 7.38.0

N/A
2018-09-05≤ 7.38.0

N/A
2019-02-06≤ 7.38.0

N/A
2019-02-06≤ 7.38.0

N/A
2020-12-14≤ 7.38.0

N/A
2020-12-14≤ 7.38.0

N/A
2021-04-01≤ 7.38.0

N/A
2023-03-30≤ 7.38.0

N/A
2023-03-30≤ 7.38.0

N/A
2023-03-30≤ 7.38.0

N/A
2023-10-18≤ 7.38.0

N/A
2024-07-31≤ 7.38.0