curl / Docs / Vulnerability table / 8.3.0 vulnerabilities

Vulnerabilities in curl 8.3.0

curl version 8.3.0 was released on September 13 2023

It has the following 18 published security problems.

FlawFrom versionTo and including
libssh key passphrase bypass without agent set7.58.08.17.0
libssh global known_hosts override7.58.08.17.0
OpenSSL partial chain store policy bypass7.87.08.17.0
bearer token leak on cross-protocol redirect7.33.08.17.0
broken TLS options for threaded LDAPS7.17.08.17.0
missing SFTP host verification with wolfSSH7.69.08.16.0
gzip integer overflow7.10.58.11.1
netrc and default credential leak7.76.08.11.1
netrc and redirect credential leak7.76.08.11.0
HSTS subdomain overwrites parent cache entry7.74.08.10.1
OCSP stapling bypass with GnuTLS7.41.08.9.1
ASN.1 date parser overread7.32.08.9.0
HTTP/2 push headers memory-leak7.44.08.6.0
Usage of disabled protocol7.85.08.6.0
HSTS long filename clears contents7.84.08.4.0
cookie mixed case PSL bypass7.46.08.4.0
cookie injection with none file7.9.18.3.0
SOCKS5 heap buffer overflow7.69.08.3.0

Further details

CVE data for 8.3.0 provided as JSON.

Changelog for curl 8.3.0

See vulnerability summary for the previous release: 8.2.1 or the subsequent release: 8.4.0