curl / Docs / Vulnerability table / 7.88.0 vulnerabilities

Vulnerabilities in curl 7.88.0

curl version 7.88.0 was released on February 15 2023

It has the following 20 published security problems.

FlawFrom versionTo and including
HSTS subdomain overwrites parent cache entry7.74.08.10.1
OCSP stapling bypass with GnuTLS7.41.08.9.1
ASN.1 date parser overread7.32.08.9.0
HTTP/2 push headers memory-leak7.44.08.6.0
Usage of disabled protocol7.85.08.6.0
HSTS long filename clears contents7.84.08.4.0
cookie mixed case PSL bypass7.46.08.4.0
cookie injection with none file7.9.18.3.0
SOCKS5 heap buffer overflow7.69.08.3.0
HTTP headers eat all memory7.84.08.2.1
more POST-after-PUT confusion7.78.0.1
IDN wildcard match7.12.08.0.1
siglongjmp race condition7.9.88.0.1
UAF in SSH sha256 fingerprint check7.81.08.0.1
SSH connection too eager reuse still7.16.17.88.1
HSTS double free7.88.07.88.1
GSS delegation too eager connection re-use7.22.07.88.1
FTP too eager connection reuse7.13.07.88.1
SFTP path ~ resolving discrepancy7.18.07.88.1
TELNET option IAC injection7.77.88.1

Futher details

CVE data for 7.88.0 provided as JSON.

Changelog for curl 7.88.0

See vulnerability summary for the previous release: 7.87.0 or the subsequent release: 7.88.1