l
libcurl
Security Risk Profile
62
/100
highSecurity Risk Score
Comprehensive risk assessment based on 9 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 21, 2005 to present
9
Total CVEs
6
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
62/100
high
Severity Distribution
Critical
2High
4Medium
1Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Buffer Overflow
2
2
Use After Free
1
Most Affected Products
1. curl libcurl65
2. libcurl libcurl32
3. haxx curl3
4. debian/curl2
5. curl curl2
Recent Vulnerabilities
See more →REDHAT-BUG-2496759
CVSS 4.0medium
Jul 3, 2026🔧 No Patch
CVE-2026-11856
CVSS 9.8critical
cross-origin Digest auth state leak
Jul 3, 2026
CVE-2026-10536
CVSS 9.8critical
HTTP/2 stream-dependency tree UAF
Jul 3, 2026
REDHAT-BUG-2426408
CVSS 1.0low
Dec 31, 2025🔧 No Patch
https://www.zdnet.com/article/security-updates-released-for-widely-used-linux-utility-curl/
unknown
Nasty bug discovered in widely used Linux utility curl, and patches already rolled out
Oct 11, 2023🔧 No Patch
CVE-2009-2417
CVSS 7.5high
Aug 14, 2009
CVE-2007-3564
CVSS 7.5high
Jul 18, 2007
CVE-2005-3185
CVSS 7.5high
Oct 13, 2005
CVE-2005-0490
CVSS 8.8high
Feb 21, 2005
Monitor libcurl in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.