curl / Docs / Vulnerability table / 7.76.0 vulnerabilities

Vulnerabilities in curl 7.76.0

curl version 7.76.0 was released on March 31 2021. The following 8 security problems are known to exist in this version.

FlawFrom versionTo and includingCVECWE
CURLOPT_SSLCERT mixup with Secure Transport7.33.07.77.0CVE-2021-22926CWE-295: Improper Certificate Validation
TELNET stack contents disclosure again7.77.77.0CVE-2021-22925CWE-457: Use of Uninitialized Variable
Bad connection reuse due to flawed path name checks7.10.47.77.0CVE-2021-22924CWE-295: Improper Certificate Validation
Metalink download sends credentials7.27.07.77.0CVE-2021-22923CWE-522: Insufficiently Protected Credentials
Wrong content via metalink not discarded7.27.07.77.0CVE-2021-22922CWE-20: Improper Input Validation
TLS session caching disaster7.75.07.76.1CVE-2021-22901CWE-416: Use After Free
TELNET stack contents disclosure7.77.76.1CVE-2021-22898CWE-457: Use of Uninitialized Variable
schannel cipher selection surprise7.61.07.76.1CVE-2021-22897CWE-488: Exposure of Data Element to Wrong Session

Changelog for curl 7.76.0

See vulnerability summary for the previous release: 7.75.0 or the subsequent release: 7.76.1