<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:35:35.801446+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:5313</id>
    <title>ALSA-2022:5313 — Moderate: curl security update</title>
    <updated>2026-10-02T17:35:36.063707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: curl, AlmaLinux:8: libcurl, AlmaLinux:8: libcurl-devel, AlmaLinux:8: libcurl-minimal</p>
<p>The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.
Security Fix(es):
* curl: OAUTH2 bearer bypass in connection re-use (CVE-2022-22576)
* curl: credential leak on redirect (CVE-2022-27774)
* curl: auth/cookie leak on redirect (CVE-2022-27776)
* curl: TLS and SSH connection too eager reuse (CVE-2022-27782)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:5313"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-03036</id>
    <title>bdu:2022-03036</title>
    <updated>2026-10-02T17:35:36.063784+00:00</updated>
    <content>bdu:2022-03036</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-03036"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-22576</id>
    <title>Withdrawn: BELL-CVE-2022-22576 — CVE-2022-22576 does not affect BellSoft software</title>
    <updated>2026-10-02T17:35:36.063801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-22576"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-570</id>
    <title>certfr-2022-avi-570 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T17:35:36.063817+00:00</updated>
    <content>certfr-2022-avi-570</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</id>
    <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
    <updated>2026-10-02T17:35:36.063831+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: curl</p>
<p>Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-321968</id>
    <title>EUVD-2026-321968</title>
    <updated>2026-10-02T17:35:36.063861+00:00</updated>
    <content>EUVD-2026-321968</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-321968"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-22576</id>
    <title>fkie_cve-2022-22576</title>
    <updated>2026-10-02T17:35:36.063872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-22576"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2r69-696x-qxj9</id>
    <title>GHSA-2r69-696x-qxj9</title>
    <updated>2026-10-02T17:35:36.063894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2r69-696x-qxj9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-22576</id>
    <title>gsd-2022-22576</title>
    <updated>2026-10-02T17:35:36.063909+00:00</updated>
    <content>gsd-2022-22576</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-22576"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-194-01</id>
    <title>ICSA-23-194-01 — Siemens RUGGEDCOM ROX</title>
    <updated>2026-10-02T17:35:36.063920+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A user can tell curl &gt;= 7.20.0 and &lt;= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network. The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-194-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-22576</id>
    <title>msrc_CVE-2022-22576 — An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-a…</title>
    <updated>2026-10-02T17:35:36.063999+00:00</updated>
    <content>msrc_CVE-2022-22576</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-22576"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1659</id>
    <title>OESA-2022-1659 — curl security update</title>
    <updated>2026-10-02T17:35:36.064016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: curl, openEuler:20.03-LTS-SP3: curl, openEuler:22.03-LTS: curl</p>
<p>cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.

Security Fix(es):

This security flaw in curl allows to reuse an OAUTH2 authenticated connection without properly ensuring that the connection is authenticated with the same credentials set by this transport, this issue can lead to authentication bypasses, either by mistake or by malicious actors.(CVE-2022-22576)</p>
<p>When asked, curl does an HTTP(S) redirect. curl also supports authentication. When providing a user and password for a URL with a given hostname, curl makes an effort not to pass these credentials to other hosts in redirects unless permissions with special options are granted. This "same host check" has been flawed since its introduction. It does not work with cross-protocol redirection, nor does it treat different port numbers as separate hosts. This results in leaking credentials to other servers when curl redirects from authentication protected HTTP(S) URLs to other protocols and port numbers. It could also leak TLS SRP credentials in this way. By default, curl only allows redirects to HTTP(S) and FTP(S), but you can ask to allow redirects to all curl-supported protocols.(CVE-2022-27774)</p>
<p>This issue with curl occurs due to a logical bug where the configuration matching function does not take into account the IPv6 address zone id, which can cause curl to reuse the wrong connection when one transfer uses the zone id and…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12028-1</id>
    <title>openSUSE-SU-2024:12028-1 — curl-7.83.0-1.1 on GA media</title>
    <updated>2026-10-02T17:35:36.064056+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl-7.83.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12028-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:1657-1</id>
    <title>SUSE-SU-2022:1657-1 — Security update for curl</title>
    <updated>2026-10-02T17:35:36.064074+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:1657-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-22576</id>
    <title>UBUNTU-CVE-2022-22576</title>
    <updated>2026-10-02T17:35:36.064090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: curl, Ubuntu:Pro:16.04:LTS: curl, Ubuntu:18.04:LTS: curl, Ubuntu:20.04:LTS: curl, Ubuntu:22.04:LTS: curl</p>
<p>An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-22576"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-046</id>
    <title>VDE-2022-046 — PHOENIX CONTACT: Multiple Linux component vulnerabilities in PLCnext Firmware</title>
    <updated>2026-10-02T17:35:36.064114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>UPDATE A: Two devices (ENERGY AXC PU, SMARTRTU AXC SG) added (24.11.2022) Update for PLCnext Firmware containing fixes for recent vulnerability findings in Linux components and security enhancements. PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2. This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-046"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0522</id>
    <title>WID-SEC-W-2022-0522 — cURL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:35:36.064160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0522"/>
  </entry>
</feed>
