curl / Docs / Vulnerability table / 7.87.0 vulnerabilities

Vulnerabilities in curl 7.87.0

curl version 7.87.0 was released on December 21 2022. The following 12 security problems are known to exist in this version.

FlawFrom versionTo and including
more POST-after-PUT confusion7.78.0.1
IDN wildcard match7.
siglongjmp race condition7.
UAF in SSH sha256 fingerprint check7.
SSH connection too eager reuse still7.
GSS delegation too eager connection re-use7.
FTP too eager connection reuse7.
SFTP path ~ resolving discrepancy7.
TELNET option IAC injection7.77.88.1
HTTP multi-header compression denial of service7.
HSTS amnesia with --parallel7.
HSTS ignored on multiple requests7.

CVE data for 7.87.0 provided as JSON.

Changelog for curl 7.87.0

See vulnerability summary for the previous release: 7.86.0 or the subsequent release: 7.88.0