curl 7.87

Status EOLSupport 2022-12 – 2023-02Latest 7.87.0Vulnerabilities 36← All curl versions
Critical 9.8
2023-03-30≤ 7.87.0

curl: TELNET option IAC injection

Critical 9.1
2023-02-23≤ 7.87.0

curl: HSTS ignored on multiple requests

High 8.8
2023-03-30≤ 7.87.0

curl: SFTP path ~ resolving discrepancy

High 8.6
2024-03-27≤ 7.87.0

HTTP/2 push headers memory-leak

High 7.5
2023-05-26≤ 7.87.0

curl: use after free in SSH sha256 fingerprint check

High 7.5
2023-09-15≤ 7.87.0

curl: out of heap memory issue due to missing limit on header quantity

High 7.3
2025-01-01≤ 7.87.0

gzip integer overflow

Medium 6.5 Unfixed
2026-03-11≤ 7.87.0

wrong proxy connection reuse with credentials

Medium 6.5 Unfixed
2026-03-11≤ 7.87.0

bad reuse of HTTP Negotiate connection

Medium 6.5
2023-02-23≤ 7.87.0

curl: HSTS amnesia with --parallel

Medium 6.5
2023-02-23≤ 7.87.0

curl: HTTP multi-header compression denial of service

Medium 6.5
2023-12-07≤ 7.87.0

curl: information disclosure by exploiting a mixed case flaw

Medium 6.5
2024-09-11≤ 7.87.0

OCSP stapling bypass with GnuTLS

Medium 6.3 Unfixed
2026-01-08≤ 7.87.0

broken TLS options for threaded LDAPS

Medium 5.9
2024-11-06≤ 7.87.0

HSTS subdomain overwrites parent cache entry

Medium 5.9
2023-05-26≤ 7.87.0

curl: siglongjmp race condition may lead to crash

Medium 5.9
2023-05-26≤ 7.87.0

curl: IDN wildcard match may lead to Improper Cerificate Validation

Medium 5.3 Unfixed
2026-04-29≤ 7.87.0

curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies

Medium 5.3 Unfixed
2026-04-29≤ 7.87.0

curl: curl: Information disclosure due to incorrect TLS connection reuse

Medium 5.3 Unfixed
2026-03-11≤ 7.87.0

token leak with redirect and netrc

Medium 5.3 Unfixed
2026-01-08≤ 7.87.0

libssh global known_hosts override

Medium 5.3 Unfixed
2026-01-08≤ 7.87.0

OpenSSL partial chain store policy bypass

Medium 5.3 Unfixed
2026-01-08≤ 7.87.0

bearer token leak on cross-protocol redirect

Medium 5.3
2023-05-26≤ 7.87.0

curl: more POST-after-PUT confusion

Medium 5.3
2023-12-12≤ 7.87.0

curl: excessively long file name may lead to unknown HSTS status

Medium 4.3 Unfixed
2025-11-07≤ 7.87.0

missing SFTP host verification with wolfSSH

Low 3.5 Unfixed
2024-03-27≤ 7.87.0

Usage of disabled protocol

Low 3.4
2025-01-01≤ 7.87.0

netrc and default credential leak

Low 3.4
2024-12-11≤ 7.87.0

netrc and redirect credential leak

Low 3.1 Unfixed
2026-01-08≤ 7.87.0

libssh key passphrase bypass without agent set

N/A
2023-03-30≤ 7.87.0

N/A
2023-03-30≤ 7.87.0

N/A
2023-03-30≤ 7.87.0

N/A
2023-10-18≤ 7.87.0

N/A
2023-10-18≤ 7.87.0

N/A
2024-07-31≤ 7.87.0