curl. An out-of-bounds read issue existed in the FTP PWD response parsing. This issue was addressed with improved bounds checking.
curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.
curl. An out-of-bounds read was addressed with improved bounds checking.
curl. An integer overflow existed in curl. This issue was addressed with improved bounds checking.
Last updated 25 August 2025
Last updated 25 August 2025