curl / Docs / Vulnerability table / 8.16.0 vulnerabilities

Vulnerabilities in curl 8.16.0

curl version 8.16.0 was released on September 10 2025

It has the following 33 published security problems.

FlawFrom versionTo and including
proto-default skips SSH verification7.81.08.20.0
cross-origin Digest auth state leak7.10.68.20.0
WS Auto-PONG memory exhaustion8.16.08.20.0
HTTP/2 stream-dependency tree UAF7.88.08.20.0
SSH improper host validation7.69.08.20.0
exposing HTTP/3 early data8.11.08.20.0
UAF after pause in socket callback8.13.08.20.0
stale proxy password leak8.8.08.20.0
incomplete mTLS config matching in conn reuse7.78.20.0
env-set cross-proxy Digest auth state leak7.12.08.20.0
password leak with netrc and user in URL8.11.18.20.0
SASL double-free8.15.08.20.0
trailing dot domain super cookie7.46.08.20.0
wrong reuse for different services7.43.08.20.0
wrong STARTTLS connection reuse7.30.08.20.0
cross-proxy Digest auth state leak7.12.08.19.0
netrc credential leak with reused proxy connection7.14.08.19.0
stale custom cookie host causes cookie leak7.71.08.19.0
proxy credentials leak over redirect-to proxy7.14.18.19.0
wrong reuse of SMB connection7.40.08.19.0
wrong reuse of HTTP Negotiate connection7.10.68.19.0
connection reuse ignores TLS requirement7.20.08.19.0
use after free in SMB connection reuse8.13.08.18.0
wrong proxy connection reuse with credentials7.78.18.0
token leak with redirect and netrc7.33.08.18.0
bad reuse of HTTP Negotiate connection7.10.68.18.0
libssh key passphrase bypass without agent set7.58.08.17.0
libssh global known_hosts override7.58.08.17.0
OpenSSL partial chain store policy bypass7.87.08.17.0
bearer token leak on cross-protocol redirect7.33.08.17.0
broken TLS options for threaded LDAPS7.17.08.17.0
No QUIC certificate pinning with GnuTLS8.8.08.17.0
missing SFTP host verification with wolfSSH7.69.08.16.0

Further details

CVE data for 8.16.0 provided as JSON.

Changelog for curl 8.16.0

See vulnerability summary for the previous release: 8.15.0 or the subsequent release: 8.17.0