curl / Docs / Vulnerability table / 7.88.0 vulnerabilities

Vulnerabilities in curl 7.88.0

curl version 7.88.0 was released on February 15 2023

It has the following 17 published security problems.

FlawFrom versionTo and including
HTTP/2 push headers memory-leak7.44.08.6.0
Usage of disabled protocol7.85.08.6.0
HSTS long filename clears contents7.84.08.4.0
cookie mixed case PSL bypass7.46.08.4.0
cookie injection with none file7.9.18.3.0
SOCKS5 heap buffer overflow7.69.08.3.0
HTTP headers eat all memory7.84.08.2.1
more POST-after-PUT confusion7.78.0.1
IDN wildcard match7.12.08.0.1
siglongjmp race condition7.9.88.0.1
UAF in SSH sha256 fingerprint check7.81.08.0.1
SSH connection too eager reuse still7.16.17.88.1
HSTS double free7.88.07.88.1
GSS delegation too eager connection re-use7.22.07.88.1
FTP too eager connection reuse7.13.07.88.1
SFTP path ~ resolving discrepancy7.18.07.88.1
TELNET option IAC injection7.77.88.1

Futher details

CVE data for 7.88.0 provided as JSON.

Changelog for curl 7.88.0

See vulnerability summary for the previous release: 7.87.0 or the subsequent release: 7.88.1