Haxx
37 known vulnerabilities
Top Products
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION`
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the document
In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transf
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerab
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the o
libcurl would reuse a previously created connection even when some mTLS config related option had been changed that shou
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(withou
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing t
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffi
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live co
When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs betwe
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then
By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service agai
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CU
Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and the
When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify t
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password use
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done u
curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following cond
libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent
libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the s
When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already free
curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses diffe
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl
libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS r
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current
When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly s
When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenl
When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a s
When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadver
When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the pu
Frequently Asked Questions
How many CVEs affect Haxx?
Haxx has 37 CVE records in our database, including 8 critical and 12 high severity vulnerabilities.
What are the most severe Haxx vulnerabilities?
Haxx has 8 critical severity (CVSS 9.0+) and 12 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Haxx vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Haxx products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Haxx Vulnerabilities
CyberStrike scans your infrastructure for Haxx vulnerabilities and provides real-time remediation guidance.
Get Started