curl 8.15

Status EOLSupport 2025-07 – 2025-09Latest 8.15.0Vulnerabilities 16← All curl versions
High 7.5 Unfixed
2026-03-11≤ 8.15.0

use after free in SMB connection reuse

High 7.5 Unfixed
2025-09-12≤ 8.15.0

Out of bounds read for cookie path

Medium 6.5 Unfixed
2026-03-11≤ 8.15.0

wrong proxy connection reuse with credentials

Medium 6.5 Unfixed
2026-03-11≤ 8.15.0

bad reuse of HTTP Negotiate connection

Medium 6.3 Unfixed
2026-01-08≤ 8.15.0

broken TLS options for threaded LDAPS

Medium 5.9 Unfixed
2026-01-08≤ 8.15.0

No QUIC certificate pinning with GnuTLS

Medium 5.3 Unfixed
2026-04-29≤ 8.15.0

curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies

Medium 5.3 Unfixed
2026-04-29≤ 8.15.0

curl: curl: Information disclosure due to incorrect TLS connection reuse

Medium 5.3 Unfixed
2026-03-11≤ 8.15.0

token leak with redirect and netrc

Medium 5.3 Unfixed
2026-01-08≤ 8.15.0

libssh global known_hosts override

Medium 5.3 Unfixed
2026-01-08≤ 8.15.0

OpenSSL partial chain store policy bypass

Medium 5.3 Unfixed
2026-01-08≤ 8.15.0

bearer token leak on cross-protocol redirect

Medium 5.3 Unfixed
2025-09-12≤ 8.15.0

predictable WebSocket mask

Medium 4.6 Unfixed
2026-02-25≤ 8.15.0

wcurl path traversal with percent-encoded slashes

Medium 4.3 Unfixed
2025-11-07≤ 8.15.0

missing SFTP host verification with wolfSSH

Low 3.1 Unfixed
2026-01-08≤ 8.15.0

libssh key passphrase bypass without agent set