<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:44:04.126077+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:0333</id>
    <title>ALSA-2023:0333 — Moderate: curl security update</title>
    <updated>2026-10-03T14:44:04.541018+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: curl, AlmaLinux:9: curl-minimal, AlmaLinux:9: libcurl, AlmaLinux:9: libcurl-devel, AlmaLinux:9: libcurl-minimal</p>
<p>The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.</p>
<p>Security Fix(es):</p>
<p>* curl: POST following PUT confusion (CVE-2022-32221)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:0333"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-07403</id>
    <title>bdu:2022-07403</title>
    <updated>2026-10-03T14:44:04.541100+00:00</updated>
    <content>bdu:2022-07403</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-07403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-32221</id>
    <title>Withdrawn: BELL-CVE-2022-32221 — CVE-2022-32221 does not affect BellSoft software</title>
    <updated>2026-10-03T14:44:04.541118+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-32221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0034</id>
    <title>certfr-2023-avi-0034 — De multiples vulnérabilités ont été découvertes dans les produits
Oracle. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T14:44:04.541134+00:00</updated>
    <content>certfr-2023-avi-0034</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</id>
    <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
    <updated>2026-10-03T14:44:04.541166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: curl</p>
<p>Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-268523</id>
    <title>EUVD-2026-268523</title>
    <updated>2026-10-03T14:44:04.541220+00:00</updated>
    <content>EUVD-2026-268523</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-268523"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-32221</id>
    <title>fkie_cve-2022-32221</title>
    <updated>2026-10-03T14:44:04.541233+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-32221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-grfr-78m7-q35q</id>
    <title>GHSA-grfr-78m7-q35q</title>
    <updated>2026-10-03T14:44:04.541258+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-grfr-78m7-q35q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-32221</id>
    <title>gsd-2022-32221</title>
    <updated>2026-10-03T14:44:04.541274+00:00</updated>
    <content>gsd-2022-32221</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-32221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-131-05</id>
    <title>ICSA-23-131-05 — Siemens SINEC NMS Third-Party</title>
    <updated>2026-10-03T14:44:04.541285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST. When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings. curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also cause different outcomes.If a malicious user can provide a custom netrc file to an application or otherwise affect its contents, this flaw could be used as denial-of-service. libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a tra…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-131-05"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-32221</id>
    <title>msrc_CVE-2022-32221 — When doing HTTP(S) transfers libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data t…</title>
    <updated>2026-10-03T14:44:04.541330+00:00</updated>
    <content>msrc_CVE-2022-32221</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-32221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-2039</id>
    <title>OESA-2022-2039 — curl security update</title>
    <updated>2026-10-03T14:44:04.541348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: curl</p>
<p>CURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.

Security Fix(es):

A vulnerability was found in curl. The issue occurs when doing HTTP(S) transfers, where curl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set if it previously used the same handle to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request.(CVE-2022-32221)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-2039"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12447-1</id>
    <title>openSUSE-SU-2024:12447-1 — curl-7.86.0-1.1 on GA media</title>
    <updated>2026-10-03T14:44:04.541371+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl-7.86.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12447-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:8840</id>
    <title>RHSA-2022:8840 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.51 SP1 security update</title>
    <updated>2026-10-03T14:44:04.541387+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: c_rehash script allows command injection openssl: the c_rehash script allows command injection httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody httpd: mod_sed: Read/write beyond bounds httpd: mod_proxy_ajp: Possible request smuggling curl: CERTINFO never-ending busy-loop httpd: Out-of-bounds read via ap_rwrite() httpd: Out-of-bounds read in ap_strcmp_match() httpd: mod_sed: DoS vulnerability httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism curl: HTTP compression denial of service curl: Unpreserved file permissions curl: FTP-KRB bad message verification curl: POST following PUT confusion curl: Incorrect handling of control code characters in cookies curl: HTTP proxy double-free curl: HSTS bypass via IDN</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:8840"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3769-1</id>
    <title>SUSE-SU-2022:3769-1 — Security update for curl</title>
    <updated>2026-10-03T14:44:04.541427+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3769-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-32221</id>
    <title>UBUNTU-CVE-2022-32221</title>
    <updated>2026-10-03T14:44:04.541442+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: curl, Ubuntu:Pro:16.04:LTS: curl, Ubuntu:18.04:LTS: curl, Ubuntu:20.04:LTS: curl, Ubuntu:22.04:LTS: curl</p>
<p>When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-32221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1862</id>
    <title>WID-SEC-W-2022-1862 — cURL: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:44:04.541477+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um einen Denial of Service zu verursachen, Informationen offenzulegen oder weitere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1862"/>
  </entry>
</feed>
