{
  "schema_version": 1,
  "series_id": "fixed-codebase-vulnerability-disclosures",
  "source_url": "https://curl.se/docs/vuln.json",
  "retrieved_at": "2026-09-15",
  "records": [
    {
      "id": "CURL-CVE-2000-0973",
      "cve": "CVE-2000-0973",
      "summary": "FTP Server Response Buffer Overflow",
      "published": "2000-10-13",
      "year": 2000,
      "quarter": 4,
      "severity": "critical",
      "finder_names": [
        "zillion"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2000-0973.html"
    },
    {
      "id": "CURL-CVE-2003-1605",
      "cve": "CVE-2003-1605",
      "summary": "Proxy Authentication Header Information Leakage",
      "published": "2003-08-03",
      "year": 2003,
      "quarter": 3,
      "severity": "high",
      "finder_names": [
        "Daniel Stenberg"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2003-1605.html"
    },
    {
      "id": "CURL-CVE-2005-0490",
      "cve": "CVE-2005-0490",
      "summary": "Authentication Buffer Overflows",
      "published": "2005-02-21",
      "year": 2005,
      "quarter": 1,
      "severity": "high",
      "finder_names": [
        "iDEFENSE"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2005-0490.html"
    },
    {
      "id": "CURL-CVE-2005-3185",
      "cve": "CVE-2005-3185",
      "summary": "NTLM Buffer Overflow",
      "published": "2005-10-13",
      "year": 2005,
      "quarter": 4,
      "severity": "high",
      "finder_names": [
        "iDEFENSE"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2005-3185.html"
    },
    {
      "id": "CURL-CVE-2005-4077",
      "cve": "CVE-2005-4077",
      "summary": "URL Buffer Overflow",
      "published": "2005-12-07",
      "year": 2005,
      "quarter": 4,
      "severity": "high",
      "finder_names": [
        "Stefan Esser"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2005-4077.html"
    },
    {
      "id": "CURL-CVE-2006-1061",
      "cve": "CVE-2006-1061",
      "summary": "TFTP Packet Buffer Overflow",
      "published": "2006-03-20",
      "year": 2006,
      "quarter": 1,
      "severity": "high",
      "finder_names": [
        "Ulf Harnhammar"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2006-1061.html"
    },
    {
      "id": "CURL-CVE-2007-3564",
      "cve": "CVE-2007-3564",
      "summary": "GnuTLS insufficient cert verification",
      "published": "2007-07-10",
      "year": 2007,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Kees Cook"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2007-3564.html"
    },
    {
      "id": "CURL-CVE-2009-0037",
      "cve": "CVE-2009-0037",
      "summary": "Arbitrary File Access",
      "published": "2009-03-03",
      "year": 2009,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "David Kierznowski"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2009-0037.html"
    },
    {
      "id": "CURL-CVE-2009-2417",
      "cve": "CVE-2009-2417",
      "summary": "embedded zero in cert name",
      "published": "2009-08-12",
      "year": 2009,
      "quarter": 3,
      "severity": "high",
      "finder_names": [
        "Scott Cantor"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2009-2417.html"
    },
    {
      "id": "CURL-CVE-2010-0734",
      "cve": "CVE-2010-0734",
      "summary": "data callback excessive length",
      "published": "2010-02-09",
      "year": 2010,
      "quarter": 1,
      "severity": "high",
      "finder_names": [
        "Wesley Miaw"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2010-0734.html"
    },
    {
      "id": "CURL-CVE-2010-3842",
      "cve": "CVE-2010-3842",
      "summary": "local file overwrite",
      "published": "2010-10-13",
      "year": 2010,
      "quarter": 4,
      "severity": "high",
      "finder_names": [
        "Dan Fandrich"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2010-3842.html"
    },
    {
      "id": "CURL-CVE-2011-2192",
      "cve": "CVE-2011-2192",
      "summary": "inappropriate GSSAPI delegation",
      "published": "2011-06-23",
      "year": 2011,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Richard Silverman"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2011-2192.html"
    },
    {
      "id": "CURL-CVE-2011-3389",
      "cve": "CVE-2011-3389",
      "summary": "SSL CBC IV vulnerability",
      "published": "2012-01-24",
      "year": 2012,
      "quarter": 1,
      "severity": "high",
      "finder_names": [
        "product-security at Apple"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2011-3389.html"
    },
    {
      "id": "CURL-CVE-2012-0036",
      "cve": "CVE-2012-0036",
      "summary": "URL sanitization vulnerability",
      "published": "2012-01-24",
      "year": 2012,
      "quarter": 1,
      "severity": "high",
      "finder_names": [
        "Dan Fandrich"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2012-0036.html"
    },
    {
      "id": "CURL-CVE-2013-0249",
      "cve": "CVE-2013-0249",
      "summary": "SASL buffer overflow",
      "published": "2013-02-06",
      "year": 2013,
      "quarter": 1,
      "severity": "critical",
      "finder_names": [
        "Volema"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2013-0249.html"
    },
    {
      "id": "CURL-CVE-2013-1944",
      "cve": "CVE-2013-1944",
      "summary": "cookie domain tailmatch",
      "published": "2013-04-12",
      "year": 2013,
      "quarter": 2,
      "severity": "high",
      "finder_names": [
        "YAMADA Yasuharu"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2013-1944.html"
    },
    {
      "id": "CURL-CVE-2013-2174",
      "cve": "CVE-2013-2174",
      "summary": "URL decode buffer boundary flaw",
      "published": "2013-06-22",
      "year": 2013,
      "quarter": 2,
      "severity": "high",
      "finder_names": [
        "Timo Sirainen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2013-2174.html"
    },
    {
      "id": "CURL-CVE-2013-4545",
      "cve": "CVE-2013-4545",
      "summary": "cert name check ignore OpenSSL",
      "published": "2013-11-15",
      "year": 2013,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Scott Cantor"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2013-4545.html"
    },
    {
      "id": "CURL-CVE-2013-6422",
      "cve": "CVE-2013-6422",
      "summary": "cert name check ignore with GnuTLS",
      "published": "2013-12-17",
      "year": 2013,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Marc Deslauriers"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2013-6422.html"
    },
    {
      "id": "CURL-CVE-2014-0015",
      "cve": "CVE-2014-0015",
      "summary": "reuse of wrong HTTP NTLM connection",
      "published": "2014-01-29",
      "year": 2014,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Paras Sethia"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2014-0015.html"
    },
    {
      "id": "CURL-CVE-2014-0138",
      "cve": "CVE-2014-0138",
      "summary": "wrong reuse of connections",
      "published": "2014-03-26",
      "year": 2014,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Steve Holme"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2014-0138.html"
    },
    {
      "id": "CURL-CVE-2014-0139",
      "cve": "CVE-2014-0139",
      "summary": "IP address wildcard certificate validation",
      "published": "2014-03-26",
      "year": 2014,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Richard Moore"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2014-0139.html"
    },
    {
      "id": "CURL-CVE-2014-1263",
      "cve": "CVE-2014-1263",
      "summary": "not verifying certs for TLS to IP address / Secure Transport",
      "published": "2014-03-26",
      "year": 2014,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Roland Moriz"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2014-1263.html"
    },
    {
      "id": "CURL-CVE-2014-2522",
      "cve": "CVE-2014-2522",
      "summary": "not verifying certs for TLS to IP address / Schannel",
      "published": "2014-03-26",
      "year": 2014,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "David Ryskalczyk"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2014-2522.html"
    },
    {
      "id": "CURL-CVE-2014-3613",
      "cve": "CVE-2014-3613",
      "summary": "cookie leak with IP address as domain",
      "published": "2014-09-10",
      "year": 2014,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Tim Ruehsen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2014-3613.html"
    },
    {
      "id": "CURL-CVE-2014-3620",
      "cve": "CVE-2014-3620",
      "summary": "cookie leak for TLDs",
      "published": "2014-09-10",
      "year": 2014,
      "quarter": 3,
      "severity": "high",
      "finder_names": [
        "Tim Ruehsen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2014-3620.html"
    },
    {
      "id": "CURL-CVE-2014-3707",
      "cve": "CVE-2014-3707",
      "summary": "duphandle read out of bounds",
      "published": "2014-11-05",
      "year": 2014,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Symeon Paraschoudis"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2014-3707.html"
    },
    {
      "id": "CURL-CVE-2014-8150",
      "cve": "CVE-2014-8150",
      "summary": "URL request injection",
      "published": "2015-01-08",
      "year": 2015,
      "quarter": 1,
      "severity": "high",
      "finder_names": [
        "Andrey Labunets (Facebook)"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2014-8150.html"
    },
    {
      "id": "CURL-CVE-2014-8151",
      "cve": "CVE-2014-8151",
      "summary": "Secure Transport certificate check bypass",
      "published": "2015-01-08",
      "year": 2015,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Marc Hesse at RethinkDB"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2014-8151.html"
    },
    {
      "id": "CURL-CVE-2015-3143",
      "cve": "CVE-2015-3143",
      "summary": "Reusing authenticated connection when unauthenticated",
      "published": "2015-04-22",
      "year": 2015,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Paras Sethia"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2015-3143.html"
    },
    {
      "id": "CURL-CVE-2015-3144",
      "cve": "CVE-2015-3144",
      "summary": "hostname out of boundary memory access",
      "published": "2015-04-22",
      "year": 2015,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Hanno Böck"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2015-3144.html"
    },
    {
      "id": "CURL-CVE-2015-3145",
      "cve": "CVE-2015-3145",
      "summary": "cookie parser out of boundary memory access",
      "published": "2015-04-22",
      "year": 2015,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Hanno Böck"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2015-3145.html"
    },
    {
      "id": "CURL-CVE-2015-3148",
      "cve": "CVE-2015-3148",
      "summary": "Negotiate not treated as connection-oriented",
      "published": "2015-04-22",
      "year": 2015,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Isaac Boukris"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2015-3148.html"
    },
    {
      "id": "CURL-CVE-2015-3153",
      "cve": "CVE-2015-3153",
      "summary": "sensitive HTTP server headers also sent to proxies",
      "published": "2015-04-29",
      "year": 2015,
      "quarter": 2,
      "severity": "high",
      "finder_names": [
        "Yehezkel Horowitz",
        "Oren Souroujon"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2015-3153.html"
    },
    {
      "id": "CURL-CVE-2015-3236",
      "cve": "CVE-2015-3236",
      "summary": "lingering HTTP credentials in connection reuse",
      "published": "2015-06-17",
      "year": 2015,
      "quarter": 2,
      "severity": "high",
      "finder_names": [
        "Tomas Tomecek",
        "Kamil Dudka"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2015-3236.html"
    },
    {
      "id": "CURL-CVE-2015-3237",
      "cve": "CVE-2015-3237",
      "summary": "SMB send off unrelated memory contents",
      "published": "2015-06-17",
      "year": 2015,
      "quarter": 2,
      "severity": "high",
      "finder_names": [
        "Daniel Stenberg"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2015-3237.html"
    },
    {
      "id": "CURL-CVE-2016-0754",
      "cve": "CVE-2016-0754",
      "summary": "remote filename path traversal in curl tool for Windows",
      "published": "2016-01-27",
      "year": 2016,
      "quarter": 1,
      "severity": "high",
      "finder_names": [
        "Ray Satiro (Jay)"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-0754.html"
    },
    {
      "id": "CURL-CVE-2016-0755",
      "cve": "CVE-2016-0755",
      "summary": "NTLM credentials not-checked for proxy connection reuse",
      "published": "2016-01-27",
      "year": 2016,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Isaac Boukris"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-0755.html"
    },
    {
      "id": "CURL-CVE-2016-3739",
      "cve": "CVE-2016-3739",
      "summary": "TLS certificate check bypass with mbedTLS/PolarSSL",
      "published": "2016-05-18",
      "year": 2016,
      "quarter": 2,
      "severity": "high",
      "finder_names": [
        "Moti Avrahami"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-3739.html"
    },
    {
      "id": "CURL-CVE-2016-4802",
      "cve": "CVE-2016-4802",
      "summary": "Windows DLL hijacking",
      "published": "2016-05-30",
      "year": 2016,
      "quarter": 2,
      "severity": "high",
      "finder_names": [
        "Guohui from Huawei WeiRan Labs"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-4802.html"
    },
    {
      "id": "CURL-CVE-2016-5419",
      "cve": "CVE-2016-5419",
      "summary": "TLS session resumption client cert bypass",
      "published": "2016-08-03",
      "year": 2016,
      "quarter": 3,
      "severity": "high",
      "finder_names": [
        "Bru Rom"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-5419.html"
    },
    {
      "id": "CURL-CVE-2016-5420",
      "cve": "CVE-2016-5420",
      "summary": "Reusing connections with wrong client cert",
      "published": "2016-08-03",
      "year": 2016,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "the curl security team"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-5420.html"
    },
    {
      "id": "CURL-CVE-2016-5421",
      "cve": "CVE-2016-5421",
      "summary": "use of connection struct after free",
      "published": "2016-08-03",
      "year": 2016,
      "quarter": 3,
      "severity": "high",
      "finder_names": [
        "Marcelo Echeverria",
        "Fernando Muñoz"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-5421.html"
    },
    {
      "id": "CURL-CVE-2016-7141",
      "cve": "CVE-2016-7141",
      "summary": "Incorrect reuse of client certificates",
      "published": "2016-09-07",
      "year": 2016,
      "quarter": 3,
      "severity": "high",
      "finder_names": [
        "Red Hat"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-7141.html"
    },
    {
      "id": "CURL-CVE-2016-7167",
      "cve": "CVE-2016-7167",
      "summary": "curl escape and unescape integer overflows",
      "published": "2016-09-14",
      "year": 2016,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "the Mitre CVE Assignment Team"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-7167.html"
    },
    {
      "id": "CURL-CVE-2016-8615",
      "cve": "CVE-2016-8615",
      "summary": "cookie injection for other servers",
      "published": "2016-11-02",
      "year": 2016,
      "quarter": 4,
      "severity": "high",
      "finder_names": [
        "Cure53"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-8615.html"
    },
    {
      "id": "CURL-CVE-2016-8616",
      "cve": "CVE-2016-8616",
      "summary": "case insensitive password comparison",
      "published": "2016-11-02",
      "year": 2016,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Cure53"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-8616.html"
    },
    {
      "id": "CURL-CVE-2016-8617",
      "cve": "CVE-2016-8617",
      "summary": "OOB write via unchecked multiplication",
      "published": "2016-11-02",
      "year": 2016,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Cure53"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-8617.html"
    },
    {
      "id": "CURL-CVE-2016-8618",
      "cve": "CVE-2016-8618",
      "summary": "double free in curl_maprintf",
      "published": "2016-11-02",
      "year": 2016,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Cure53"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-8618.html"
    },
    {
      "id": "CURL-CVE-2016-8619",
      "cve": "CVE-2016-8619",
      "summary": "double free in krb5 code",
      "published": "2016-11-02",
      "year": 2016,
      "quarter": 4,
      "severity": "high",
      "finder_names": [
        "Cure53"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-8619.html"
    },
    {
      "id": "CURL-CVE-2016-8620",
      "cve": "CVE-2016-8620",
      "summary": "glob parser write/read out of bounds",
      "published": "2016-11-02",
      "year": 2016,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Luật Nguyễn"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-8620.html"
    },
    {
      "id": "CURL-CVE-2016-8621",
      "cve": "CVE-2016-8621",
      "summary": "curl_getdate read out of bounds",
      "published": "2016-11-02",
      "year": 2016,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Luật Nguyễn"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-8621.html"
    },
    {
      "id": "CURL-CVE-2016-8622",
      "cve": "CVE-2016-8622",
      "summary": "URL unescape heap overflow via integer truncation",
      "published": "2016-11-02",
      "year": 2016,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Cure53"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-8622.html"
    },
    {
      "id": "CURL-CVE-2016-8623",
      "cve": "CVE-2016-8623",
      "summary": "Use after free via shared cookies",
      "published": "2016-11-02",
      "year": 2016,
      "quarter": 4,
      "severity": "high",
      "finder_names": [
        "Cure53"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-8623.html"
    },
    {
      "id": "CURL-CVE-2016-8624",
      "cve": "CVE-2016-8624",
      "summary": "invalid URL parsing with '#'",
      "published": "2016-11-02",
      "year": 2016,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Fernando Muñoz"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-8624.html"
    },
    {
      "id": "CURL-CVE-2016-8625",
      "cve": "CVE-2016-8625",
      "summary": "IDNA 2003 makes curl use wrong host",
      "published": "2016-11-02",
      "year": 2016,
      "quarter": 4,
      "severity": "high",
      "finder_names": [
        "Christian Heimes"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-8625.html"
    },
    {
      "id": "CURL-CVE-2016-9586",
      "cve": "CVE-2016-9586",
      "summary": "printf floating point buffer overflow",
      "published": "2016-12-21",
      "year": 2016,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Daniel Stenberg"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-9586.html"
    },
    {
      "id": "CURL-CVE-2016-9952",
      "cve": "CVE-2016-9952",
      "summary": "Win CE Schannel cert wildcard matches too much",
      "published": "2016-12-21",
      "year": 2016,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Dan McNulty"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-9952.html"
    },
    {
      "id": "CURL-CVE-2016-9953",
      "cve": "CVE-2016-9953",
      "summary": "Win CE Schannel cert name out of buffer read",
      "published": "2016-12-21",
      "year": 2016,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Dan McNulty"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-9953.html"
    },
    {
      "id": "CURL-CVE-2016-9594",
      "cve": "CVE-2016-9594",
      "summary": "uninitialized random",
      "published": "2016-12-23",
      "year": 2016,
      "quarter": 4,
      "severity": "high",
      "finder_names": [
        "Kamil Dudka"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2016-9594.html"
    },
    {
      "id": "CURL-CVE-2017-2629",
      "cve": "CVE-2017-2629",
      "summary": "SSL_VERIFYSTATUS ignored",
      "published": "2017-02-22",
      "year": 2017,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Marcus Hoffmann"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2017-2629.html"
    },
    {
      "id": "CURL-CVE-2017-7407",
      "cve": "CVE-2017-7407",
      "summary": "--write-out out of buffer read",
      "published": "2017-04-03",
      "year": 2017,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Brian Carpenter (Geeknik Labs)"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2017-7407.html"
    },
    {
      "id": "CURL-CVE-2017-7468",
      "cve": "CVE-2017-7468",
      "summary": "TLS session resumption client cert bypass (again)",
      "published": "2017-04-19",
      "year": 2017,
      "quarter": 2,
      "severity": "high",
      "finder_names": [
        "lijian996 on github"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2017-7468.html"
    },
    {
      "id": "CURL-CVE-2017-9502",
      "cve": "CVE-2017-9502",
      "summary": "URL file scheme drive letter buffer overflow",
      "published": "2017-06-14",
      "year": 2017,
      "quarter": 2,
      "severity": "high",
      "finder_names": [
        "Marcel Raad"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2017-9502.html"
    },
    {
      "id": "CURL-CVE-2017-1000099",
      "cve": "CVE-2017-1000099",
      "summary": "FILE buffer read out of bounds",
      "published": "2017-08-09",
      "year": 2017,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Even Rouault"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2017-1000099.html"
    },
    {
      "id": "CURL-CVE-2017-1000100",
      "cve": "CVE-2017-1000100",
      "summary": "TFTP sends more than buffer size",
      "published": "2017-08-09",
      "year": 2017,
      "quarter": 3,
      "severity": "high",
      "finder_names": [
        "Even Rouault"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2017-1000100.html"
    },
    {
      "id": "CURL-CVE-2017-1000101",
      "cve": "CVE-2017-1000101",
      "summary": "URL globbing out of bounds read",
      "published": "2017-08-09",
      "year": 2017,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Brian Carpenter",
        "Yongji Ouyang"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2017-1000101.html"
    },
    {
      "id": "CURL-CVE-2017-1000254",
      "cve": "CVE-2017-1000254",
      "summary": "FTP PWD response parser out of bounds read",
      "published": "2017-10-04",
      "year": 2017,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Max Dymond"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2017-1000254.html"
    },
    {
      "id": "CURL-CVE-2017-1000257",
      "cve": "CVE-2017-1000257",
      "summary": "IMAP FETCH response out of bounds read",
      "published": "2017-10-23",
      "year": 2017,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Brian Carpenter (Geeknik Labs)",
        "0xd34db347"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2017-1000257.html"
    },
    {
      "id": "CURL-CVE-2017-8816",
      "cve": "CVE-2017-8816",
      "summary": "NTLM buffer overflow via integer overflow",
      "published": "2017-11-29",
      "year": 2017,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Alex Nichols"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2017-8816.html"
    },
    {
      "id": "CURL-CVE-2017-8817",
      "cve": "CVE-2017-8817",
      "summary": "FTP wildcard out of bounds read",
      "published": "2017-11-29",
      "year": 2017,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "OSS-Fuzz"
      ],
      "attribution_band": "fuzzing_marker",
      "attribution_markers": [
        "OSS-Fuzz",
        "fuzzing"
      ],
      "source_url": "https://curl.se/docs/CVE-2017-8817.html"
    },
    {
      "id": "CURL-CVE-2017-8818",
      "cve": "CVE-2017-8818",
      "summary": "SSL out of buffer access",
      "published": "2017-11-29",
      "year": 2017,
      "quarter": 4,
      "severity": "high",
      "finder_names": [
        "John Schoenick"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2017-8818.html"
    },
    {
      "id": "CURL-CVE-2018-1000005",
      "cve": "CVE-2018-1000005",
      "summary": "HTTP/2 trailer out-of-bounds read",
      "published": "2018-01-24",
      "year": 2018,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Zhouyihai Ding"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2018-1000005.html"
    },
    {
      "id": "CURL-CVE-2018-1000007",
      "cve": "CVE-2018-1000007",
      "summary": "HTTP authentication leak in redirects",
      "published": "2018-01-24",
      "year": 2018,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Craig de Stigter"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2018-1000007.html"
    },
    {
      "id": "CURL-CVE-2018-1000120",
      "cve": "CVE-2018-1000120",
      "summary": "FTP path trickery leads to NIL byte out of bounds write",
      "published": "2018-03-14",
      "year": 2018,
      "quarter": 1,
      "severity": "high",
      "finder_names": [
        "Duy Phan Thanh"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2018-1000120.html"
    },
    {
      "id": "CURL-CVE-2018-1000121",
      "cve": "CVE-2018-1000121",
      "summary": "LDAP NULL pointer dereference",
      "published": "2018-03-14",
      "year": 2018,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Dario Weisser"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2018-1000121.html"
    },
    {
      "id": "CURL-CVE-2018-1000122",
      "cve": "CVE-2018-1000122",
      "summary": "RTSP RTP buffer over-read",
      "published": "2018-03-14",
      "year": 2018,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "OSS-fuzz"
      ],
      "attribution_band": "fuzzing_marker",
      "attribution_markers": [
        "OSS-Fuzz",
        "fuzzing"
      ],
      "source_url": "https://curl.se/docs/CVE-2018-1000122.html"
    },
    {
      "id": "CURL-CVE-2018-1000300",
      "cve": "CVE-2018-1000300",
      "summary": "FTP shutdown response buffer overflow",
      "published": "2018-05-16",
      "year": 2018,
      "quarter": 2,
      "severity": "high",
      "finder_names": [
        "Dario Weisser"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2018-1000300.html"
    },
    {
      "id": "CURL-CVE-2018-1000301",
      "cve": "CVE-2018-1000301",
      "summary": "RTSP bad headers buffer over-read",
      "published": "2018-05-16",
      "year": 2018,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "OSS-Fuzz"
      ],
      "attribution_band": "fuzzing_marker",
      "attribution_markers": [
        "OSS-Fuzz",
        "fuzzing"
      ],
      "source_url": "https://curl.se/docs/CVE-2018-1000301.html"
    },
    {
      "id": "CURL-CVE-2018-0500",
      "cve": "CVE-2018-0500",
      "summary": "SMTP send heap buffer overflow",
      "published": "2018-07-11",
      "year": 2018,
      "quarter": 3,
      "severity": "high",
      "finder_names": [
        "Peter Wu"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2018-0500.html"
    },
    {
      "id": "CURL-CVE-2018-14618",
      "cve": "CVE-2018-14618",
      "summary": "NTLM password overflow via integer overflow",
      "published": "2018-09-05",
      "year": 2018,
      "quarter": 3,
      "severity": "high",
      "finder_names": [
        "Zhaoyang Wu"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2018-14618.html"
    },
    {
      "id": "CURL-CVE-2018-16839",
      "cve": "CVE-2018-16839",
      "summary": "SASL password overflow via integer overflow",
      "published": "2018-10-31",
      "year": 2018,
      "quarter": 4,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2018-16839.html"
    },
    {
      "id": "CURL-CVE-2018-16840",
      "cve": "CVE-2018-16840",
      "summary": "use after free in handle close",
      "published": "2018-10-31",
      "year": 2018,
      "quarter": 4,
      "severity": "low",
      "finder_names": [
        "Brian Carpenter (Geeknik Labs)"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2018-16840.html"
    },
    {
      "id": "CURL-CVE-2018-16842",
      "cve": "CVE-2018-16842",
      "summary": "warning message out-of-buffer read",
      "published": "2018-10-31",
      "year": 2018,
      "quarter": 4,
      "severity": "low",
      "finder_names": [
        "Brian Carpenter (Geeknik Labs)"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2018-16842.html"
    },
    {
      "id": "CURL-CVE-2018-16890",
      "cve": "CVE-2018-16890",
      "summary": "NTLM type-2 out-of-bounds buffer read",
      "published": "2019-02-06",
      "year": 2019,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Wenxiang Qian of Tencent Blade Team"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2018-16890.html"
    },
    {
      "id": "CURL-CVE-2019-3822",
      "cve": "CVE-2019-3822",
      "summary": "NTLMv2 type-3 header stack buffer overflow",
      "published": "2019-02-06",
      "year": 2019,
      "quarter": 1,
      "severity": "high",
      "finder_names": [
        "Wenxiang Qian of Tencent Blade Team"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2019-3822.html"
    },
    {
      "id": "CURL-CVE-2019-3823",
      "cve": "CVE-2019-3823",
      "summary": "SMTP end-of-response out-of-bounds read",
      "published": "2019-02-06",
      "year": 2019,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Brian Carpenter (Geeknik Labs)"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2019-3823.html"
    },
    {
      "id": "CURL-CVE-2019-5435",
      "cve": "CVE-2019-5435",
      "summary": "Integer overflows in URL parser",
      "published": "2019-05-22",
      "year": 2019,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Wenchao Li"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2019-5435.html"
    },
    {
      "id": "CURL-CVE-2019-5436",
      "cve": "CVE-2019-5436",
      "summary": "TFTP receive buffer overflow",
      "published": "2019-05-22",
      "year": 2019,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "l00p3r"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2019-5436.html"
    },
    {
      "id": "CURL-CVE-2019-5443",
      "cve": "CVE-2019-5443",
      "summary": "Windows OpenSSL engine code injection",
      "published": "2019-06-24",
      "year": 2019,
      "quarter": 2,
      "severity": "high",
      "finder_names": [
        "Rich Mirch"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2019-5443.html"
    },
    {
      "id": "CURL-CVE-2019-5481",
      "cve": "CVE-2019-5481",
      "summary": "FTP-KRB double free",
      "published": "2019-09-11",
      "year": 2019,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Thomas Vegas"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2019-5481.html"
    },
    {
      "id": "CURL-CVE-2019-5482",
      "cve": "CVE-2019-5482",
      "summary": "TFTP small blocksize heap buffer overflow",
      "published": "2019-09-11",
      "year": 2019,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Thomas Vegas"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2019-5482.html"
    },
    {
      "id": "CURL-CVE-2020-8169",
      "cve": "CVE-2020-8169",
      "summary": "Partial password leak over DNS on HTTP redirect",
      "published": "2020-06-24",
      "year": 2020,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Marek Szlagor",
        "Gregory Jefferis",
        "Jeroen Ooms"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2020-8169.html"
    },
    {
      "id": "CURL-CVE-2020-8177",
      "cve": "CVE-2020-8177",
      "summary": "curl overwrite local file with -J",
      "published": "2020-06-24",
      "year": 2020,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "sn on hackerone"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2020-8177.html"
    },
    {
      "id": "CURL-CVE-2020-8231",
      "cve": "CVE-2020-8231",
      "summary": "wrong connect-only connection",
      "published": "2020-08-19",
      "year": 2020,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Marc Aldorasi"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2020-8231.html"
    },
    {
      "id": "CURL-CVE-2020-8284",
      "cve": "CVE-2020-8284",
      "summary": "trusting FTP PASV responses",
      "published": "2020-12-09",
      "year": 2020,
      "quarter": 4,
      "severity": "low",
      "finder_names": [
        "Varnavas Papaioannou"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2020-8284.html"
    },
    {
      "id": "CURL-CVE-2020-8285",
      "cve": "CVE-2020-8285",
      "summary": "FTP wildcard stack overflow",
      "published": "2020-12-09",
      "year": 2020,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "xnynx on github"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2020-8285.html"
    },
    {
      "id": "CURL-CVE-2020-8286",
      "cve": "CVE-2020-8286",
      "summary": "Inferior OCSP verification",
      "published": "2020-12-09",
      "year": 2020,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Ospoco"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2020-8286.html"
    },
    {
      "id": "CURL-CVE-2021-22876",
      "cve": "CVE-2021-22876",
      "summary": "Automatic referer leaks credentials",
      "published": "2021-03-31",
      "year": 2021,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Viktor Szakats"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22876.html"
    },
    {
      "id": "CURL-CVE-2021-22890",
      "cve": "CVE-2021-22890",
      "summary": "TLS 1.3 session ticket proxy host mix-up",
      "published": "2021-03-31",
      "year": 2021,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Mingtao Yang (Facebook)"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22890.html"
    },
    {
      "id": "CURL-CVE-2021-22897",
      "cve": "CVE-2021-22897",
      "summary": "Schannel cipher selection surprise",
      "published": "2021-05-26",
      "year": 2021,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22897.html"
    },
    {
      "id": "CURL-CVE-2021-22898",
      "cve": "CVE-2021-22898",
      "summary": "TELNET stack contents disclosure",
      "published": "2021-05-26",
      "year": 2021,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22898.html"
    },
    {
      "id": "CURL-CVE-2021-22901",
      "cve": "CVE-2021-22901",
      "summary": "TLS session caching disaster",
      "published": "2021-05-26",
      "year": 2021,
      "quarter": 2,
      "severity": "high",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22901.html"
    },
    {
      "id": "CURL-CVE-2021-22922",
      "cve": "CVE-2021-22922",
      "summary": "Wrong content via Metalink not discarded",
      "published": "2021-07-21",
      "year": 2021,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22922.html"
    },
    {
      "id": "CURL-CVE-2021-22923",
      "cve": "CVE-2021-22923",
      "summary": "Metalink download sends credentials",
      "published": "2021-07-21",
      "year": 2021,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22923.html"
    },
    {
      "id": "CURL-CVE-2021-22924",
      "cve": "CVE-2021-22924",
      "summary": "Bad connection reuse due to flawed path name checks",
      "published": "2021-07-21",
      "year": 2021,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22924.html"
    },
    {
      "id": "CURL-CVE-2021-22925",
      "cve": "CVE-2021-22925",
      "summary": "TELNET stack contents disclosure again",
      "published": "2021-07-21",
      "year": 2021,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Red Hat Product Security"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22925.html"
    },
    {
      "id": "CURL-CVE-2021-22926",
      "cve": "CVE-2021-22926",
      "summary": "CURLOPT_SSLCERT mix-up with Secure Transport",
      "published": "2021-07-21",
      "year": 2021,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22926.html"
    },
    {
      "id": "CURL-CVE-2021-22945",
      "cve": "CVE-2021-22945",
      "summary": "UAF and double free in MQTT sending",
      "published": "2021-09-15",
      "year": 2021,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "z2_"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22945.html"
    },
    {
      "id": "CURL-CVE-2021-22946",
      "cve": "CVE-2021-22946",
      "summary": "Protocol downgrade required TLS bypassed",
      "published": "2021-09-15",
      "year": 2021,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Patrick Monnerat"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22946.html"
    },
    {
      "id": "CURL-CVE-2021-22947",
      "cve": "CVE-2021-22947",
      "summary": "STARTTLS protocol injection via MITM",
      "published": "2021-09-15",
      "year": 2021,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Patrick Monnerat"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2021-22947.html"
    },
    {
      "id": "CURL-CVE-2022-22576",
      "cve": "CVE-2022-22576",
      "summary": "OAUTH2 bearer bypass in connection reuse",
      "published": "2022-04-27",
      "year": 2022,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Patrick Monnerat"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-22576.html"
    },
    {
      "id": "CURL-CVE-2022-27774",
      "cve": "CVE-2022-27774",
      "summary": "Credential leak on redirect",
      "published": "2022-04-27",
      "year": 2022,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-27774.html"
    },
    {
      "id": "CURL-CVE-2022-27775",
      "cve": "CVE-2022-27775",
      "summary": "Bad local IPv6 connection reuse",
      "published": "2022-04-27",
      "year": 2022,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-27775.html"
    },
    {
      "id": "CURL-CVE-2022-27776",
      "cve": "CVE-2022-27776",
      "summary": "Auth/cookie leak on redirect",
      "published": "2022-04-27",
      "year": 2022,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-27776.html"
    },
    {
      "id": "CURL-CVE-2022-27778",
      "cve": "CVE-2022-27778",
      "summary": "curl removes wrong file on error",
      "published": "2022-05-11",
      "year": 2022,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-27778.html"
    },
    {
      "id": "CURL-CVE-2022-27779",
      "cve": "CVE-2022-27779",
      "summary": "cookie for trailing dot TLD",
      "published": "2022-05-11",
      "year": 2022,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Axel Chong"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-27779.html"
    },
    {
      "id": "CURL-CVE-2022-27780",
      "cve": "CVE-2022-27780",
      "summary": "percent-encoded path separator in URL host",
      "published": "2022-05-11",
      "year": 2022,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Axel Chong"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-27780.html"
    },
    {
      "id": "CURL-CVE-2022-27781",
      "cve": "CVE-2022-27781",
      "summary": "CERTINFO never-ending busy-loop",
      "published": "2022-05-11",
      "year": 2022,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Florian Kohnhäuser"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-27781.html"
    },
    {
      "id": "CURL-CVE-2022-27782",
      "cve": "CVE-2022-27782",
      "summary": "TLS and SSH connection too eager reuse",
      "published": "2022-05-11",
      "year": 2022,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-27782.html"
    },
    {
      "id": "CURL-CVE-2022-30115",
      "cve": "CVE-2022-30115",
      "summary": "HSTS bypass via trailing dot",
      "published": "2022-05-11",
      "year": 2022,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Axel Chong"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-30115.html"
    },
    {
      "id": "CURL-CVE-2022-32205",
      "cve": "CVE-2022-32205",
      "summary": "Set-Cookie denial of service",
      "published": "2022-06-27",
      "year": 2022,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-32205.html"
    },
    {
      "id": "CURL-CVE-2022-32206",
      "cve": "CVE-2022-32206",
      "summary": "HTTP compression denial of service",
      "published": "2022-06-27",
      "year": 2022,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-32206.html"
    },
    {
      "id": "CURL-CVE-2022-32207",
      "cve": "CVE-2022-32207",
      "summary": "Non-preserved file permissions",
      "published": "2022-06-27",
      "year": 2022,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-32207.html"
    },
    {
      "id": "CURL-CVE-2022-32208",
      "cve": "CVE-2022-32208",
      "summary": "FTP-KRB bad message verification",
      "published": "2022-06-27",
      "year": 2022,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-32208.html"
    },
    {
      "id": "CURL-CVE-2022-35252",
      "cve": "CVE-2022-35252",
      "summary": "control code in cookie denial of service",
      "published": "2022-08-31",
      "year": 2022,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Axel Chong"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-35252.html"
    },
    {
      "id": "CURL-CVE-2022-32221",
      "cve": "CVE-2022-32221",
      "summary": "POST following PUT confusion",
      "published": "2022-10-26",
      "year": 2022,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Robby Simpson"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-32221.html"
    },
    {
      "id": "CURL-CVE-2022-35260",
      "cve": "CVE-2022-35260",
      "summary": ".netrc parser out-of-bounds access",
      "published": "2022-10-26",
      "year": 2022,
      "quarter": 4,
      "severity": "low",
      "finder_names": [
        "Hiroki Kurosawa"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-35260.html"
    },
    {
      "id": "CURL-CVE-2022-42915",
      "cve": "CVE-2022-42915",
      "summary": "HTTP proxy double free",
      "published": "2022-10-26",
      "year": 2022,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Trail of Bits"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-42915.html"
    },
    {
      "id": "CURL-CVE-2022-42916",
      "cve": "CVE-2022-42916",
      "summary": "HSTS bypass via IDN",
      "published": "2022-10-26",
      "year": 2022,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Hiroki Kurosawa"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-42916.html"
    },
    {
      "id": "CURL-CVE-2022-43551",
      "cve": "CVE-2022-43551",
      "summary": "Another HSTS bypass via IDN",
      "published": "2022-12-21",
      "year": 2022,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Hiroki Kurosawa"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-43551.html"
    },
    {
      "id": "CURL-CVE-2022-43552",
      "cve": "CVE-2022-43552",
      "summary": "HTTP Proxy deny use after free",
      "published": "2022-12-21",
      "year": 2022,
      "quarter": 4,
      "severity": "low",
      "finder_names": [
        "Trail of Bits"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2022-43552.html"
    },
    {
      "id": "CURL-CVE-2023-23914",
      "cve": "CVE-2023-23914",
      "summary": "HSTS ignored on multiple requests",
      "published": "2023-02-15",
      "year": 2023,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-23914.html"
    },
    {
      "id": "CURL-CVE-2023-23915",
      "cve": "CVE-2023-23915",
      "summary": "HSTS amnesia with --parallel",
      "published": "2023-02-15",
      "year": 2023,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-23915.html"
    },
    {
      "id": "CURL-CVE-2023-23916",
      "cve": "CVE-2023-23916",
      "summary": "HTTP multi-header compression denial of service",
      "published": "2023-02-15",
      "year": 2023,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Patrick Monnerat"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-23916.html"
    },
    {
      "id": "CURL-CVE-2023-27533",
      "cve": "CVE-2023-27533",
      "summary": "TELNET option IAC injection",
      "published": "2023-03-20",
      "year": 2023,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-27533.html"
    },
    {
      "id": "CURL-CVE-2023-27534",
      "cve": "CVE-2023-27534",
      "summary": "SFTP path ~ resolving discrepancy",
      "published": "2023-03-20",
      "year": 2023,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-27534.html"
    },
    {
      "id": "CURL-CVE-2023-27535",
      "cve": "CVE-2023-27535",
      "summary": "FTP too eager connection reuse",
      "published": "2023-03-20",
      "year": 2023,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-27535.html"
    },
    {
      "id": "CURL-CVE-2023-27536",
      "cve": "CVE-2023-27536",
      "summary": "GSS delegation too eager connection reuse",
      "published": "2023-03-20",
      "year": 2023,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-27536.html"
    },
    {
      "id": "CURL-CVE-2023-27537",
      "cve": "CVE-2023-27537",
      "summary": "HSTS double free",
      "published": "2023-03-20",
      "year": 2023,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Hiroki Kurosawa"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-27537.html"
    },
    {
      "id": "CURL-CVE-2023-27538",
      "cve": "CVE-2023-27538",
      "summary": "SSH connection too eager reuse still",
      "published": "2023-03-20",
      "year": 2023,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-27538.html"
    },
    {
      "id": "CURL-CVE-2023-28319",
      "cve": "CVE-2023-28319",
      "summary": "UAF in SSH sha256 fingerprint check",
      "published": "2023-05-17",
      "year": 2023,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Wei Chong Tan"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-28319.html"
    },
    {
      "id": "CURL-CVE-2023-28320",
      "cve": "CVE-2023-28320",
      "summary": "siglongjmp race condition",
      "published": "2023-05-17",
      "year": 2023,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-28320.html"
    },
    {
      "id": "CURL-CVE-2023-28321",
      "cve": "CVE-2023-28321",
      "summary": "IDN wildcard match",
      "published": "2023-05-17",
      "year": 2023,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Hiroki Kurosawa"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-28321.html"
    },
    {
      "id": "CURL-CVE-2023-28322",
      "cve": "CVE-2023-28322",
      "summary": "more POST-after-PUT confusion",
      "published": "2023-05-17",
      "year": 2023,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Hiroki Kurosawa"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-28322.html"
    },
    {
      "id": "CURL-CVE-2023-38039",
      "cve": "CVE-2023-38039",
      "summary": "HTTP headers eat all memory",
      "published": "2023-09-13",
      "year": 2023,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "selmelc on hackerone"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-38039.html"
    },
    {
      "id": "CURL-CVE-2023-38545",
      "cve": "CVE-2023-38545",
      "summary": "SOCKS5 heap buffer overflow",
      "published": "2023-10-11",
      "year": 2023,
      "quarter": 4,
      "severity": "high",
      "finder_names": [
        "Jay Satiro"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-38545.html"
    },
    {
      "id": "CURL-CVE-2023-38546",
      "cve": "CVE-2023-38546",
      "summary": "cookie injection with none file",
      "published": "2023-10-11",
      "year": 2023,
      "quarter": 4,
      "severity": "low",
      "finder_names": [
        "w0x42 on hackerone"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-38546.html"
    },
    {
      "id": "CURL-CVE-2023-46218",
      "cve": "CVE-2023-46218",
      "summary": "cookie mixed case PSL bypass",
      "published": "2023-12-06",
      "year": 2023,
      "quarter": 4,
      "severity": "medium",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-46218.html"
    },
    {
      "id": "CURL-CVE-2023-46219",
      "cve": "CVE-2023-46219",
      "summary": "HSTS long filename clears contents",
      "published": "2023-12-06",
      "year": 2023,
      "quarter": 4,
      "severity": "low",
      "finder_names": [
        "Maksymilian Arciemowicz"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2023-46219.html"
    },
    {
      "id": "CURL-CVE-2024-0853",
      "cve": "CVE-2024-0853",
      "summary": "OCSP verification bypass with TLS session reuse",
      "published": "2024-01-31",
      "year": 2024,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Hiroki Kurosawa"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2024-0853.html"
    },
    {
      "id": "CURL-CVE-2024-2004",
      "cve": "CVE-2024-2004",
      "summary": "Usage of disabled protocol",
      "published": "2024-03-27",
      "year": 2024,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Dan Fandrich"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2024-2004.html"
    },
    {
      "id": "CURL-CVE-2024-2379",
      "cve": "CVE-2024-2379",
      "summary": "QUIC certificate check bypass with wolfSSL",
      "published": "2024-03-27",
      "year": 2024,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Dexter Gerig"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2024-2379.html"
    },
    {
      "id": "CURL-CVE-2024-2398",
      "cve": "CVE-2024-2398",
      "summary": "HTTP/2 push headers memory-leak",
      "published": "2024-03-27",
      "year": 2024,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "w0x42 on hackerone"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2024-2398.html"
    },
    {
      "id": "CURL-CVE-2024-2466",
      "cve": "CVE-2024-2466",
      "summary": "TLS certificate check bypass with mbedTLS",
      "published": "2024-03-27",
      "year": 2024,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Frank Yueh"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2024-2466.html"
    },
    {
      "id": "CURL-CVE-2024-6197",
      "cve": "CVE-2024-6197",
      "summary": "freeing stack buffer in utf8asn1str",
      "published": "2024-07-24",
      "year": 2024,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "z2_"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2024-6197.html"
    },
    {
      "id": "CURL-CVE-2024-6874",
      "cve": "CVE-2024-6874",
      "summary": "macidn punycode buffer overread",
      "published": "2024-07-24",
      "year": 2024,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "z2_"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2024-6874.html"
    },
    {
      "id": "CURL-CVE-2024-7264",
      "cve": "CVE-2024-7264",
      "summary": "ASN.1 date parser overread",
      "published": "2024-07-31",
      "year": 2024,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Dov Murik (Transmit Security)"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2024-7264.html"
    },
    {
      "id": "CURL-CVE-2024-8096",
      "cve": "CVE-2024-8096",
      "summary": "OCSP stapling bypass with GnuTLS",
      "published": "2024-09-11",
      "year": 2024,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Hiroki Kurosawa"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2024-8096.html"
    },
    {
      "id": "CURL-CVE-2024-9681",
      "cve": "CVE-2024-9681",
      "summary": "HSTS subdomain overwrites parent cache entry",
      "published": "2024-11-06",
      "year": 2024,
      "quarter": 4,
      "severity": "low",
      "finder_names": [
        "newfunction"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2024-9681.html"
    },
    {
      "id": "CURL-CVE-2024-11053",
      "cve": "CVE-2024-11053",
      "summary": "netrc and redirect credential leak",
      "published": "2024-12-11",
      "year": 2024,
      "quarter": 4,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2024-11053.html"
    },
    {
      "id": "CURL-CVE-2025-0167",
      "cve": "CVE-2025-0167",
      "summary": "netrc and default credential leak",
      "published": "2025-02-05",
      "year": 2025,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Yihang Zhou"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2025-0167.html"
    },
    {
      "id": "CURL-CVE-2025-0665",
      "cve": "CVE-2025-0665",
      "summary": "eventfd double close",
      "published": "2025-02-05",
      "year": 2025,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Ankom Coper",
        "Christian Heusel"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2025-0665.html"
    },
    {
      "id": "CURL-CVE-2025-0725",
      "cve": "CVE-2025-0725",
      "summary": "gzip integer overflow",
      "published": "2025-02-05",
      "year": 2025,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "z2_"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2025-0725.html"
    },
    {
      "id": "CURL-CVE-2025-4947",
      "cve": "CVE-2025-4947",
      "summary": "QUIC certificate check skip with wolfSSL",
      "published": "2025-05-28",
      "year": 2025,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Hiroki Kurosawa"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2025-4947.html"
    },
    {
      "id": "CURL-CVE-2025-5025",
      "cve": "CVE-2025-5025",
      "summary": "No QUIC certificate pinning with wolfSSL",
      "published": "2025-05-28",
      "year": 2025,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Hiroki Kurosawa"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2025-5025.html"
    },
    {
      "id": "CURL-CVE-2025-5399",
      "cve": "CVE-2025-5399",
      "summary": "WebSocket endless loop",
      "published": "2025-06-04",
      "year": 2025,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "z2_ on hackerone"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2025-5399.html"
    },
    {
      "id": "CURL-CVE-2025-10148",
      "cve": "CVE-2025-10148",
      "summary": "predictable WebSocket mask",
      "published": "2025-09-10",
      "year": 2025,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Calvin Ruocco (Vector Informatik GmbH)"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2025-10148.html"
    },
    {
      "id": "CURL-CVE-2025-9086",
      "cve": "CVE-2025-9086",
      "summary": "Out of bounds read for cookie path",
      "published": "2025-09-10",
      "year": 2025,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Google Big Sleep"
      ],
      "attribution_band": "explicit_ai_marker",
      "attribution_markers": [
        "Big Sleep"
      ],
      "source_url": "https://curl.se/docs/CVE-2025-9086.html"
    },
    {
      "id": "CURL-CVE-2025-10966",
      "cve": "CVE-2025-10966",
      "summary": "missing SFTP host verification with wolfSSH",
      "published": "2025-11-05",
      "year": 2025,
      "quarter": 4,
      "severity": "low",
      "finder_names": [
        "Stanislav Fort (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2025-10966.html"
    },
    {
      "id": "CURL-CVE-2025-13034",
      "cve": "CVE-2025-13034",
      "summary": "No QUIC certificate pinning with GnuTLS",
      "published": "2026-01-07",
      "year": 2026,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Stanislav Fort (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2025-13034.html"
    },
    {
      "id": "CURL-CVE-2025-14017",
      "cve": "CVE-2025-14017",
      "summary": "broken TLS options for threaded LDAPS",
      "published": "2026-01-07",
      "year": 2026,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Stanislav Fort (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2025-14017.html"
    },
    {
      "id": "CURL-CVE-2025-14524",
      "cve": "CVE-2025-14524",
      "summary": "bearer token leak on cross-protocol redirect",
      "published": "2026-01-07",
      "year": 2026,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "anonymous237 on hackerone"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2025-14524.html"
    },
    {
      "id": "CURL-CVE-2025-14819",
      "cve": "CVE-2025-14819",
      "summary": "OpenSSL partial chain store policy bypass",
      "published": "2026-01-07",
      "year": 2026,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Stanislav Fort (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2025-14819.html"
    },
    {
      "id": "CURL-CVE-2025-15079",
      "cve": "CVE-2025-15079",
      "summary": "libssh global known_hosts override",
      "published": "2026-01-07",
      "year": 2026,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2025-15079.html"
    },
    {
      "id": "CURL-CVE-2025-15224",
      "cve": "CVE-2025-15224",
      "summary": "libssh key passphrase bypass without agent set",
      "published": "2026-01-07",
      "year": 2026,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Harry Sintonen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2025-15224.html"
    },
    {
      "id": "CURL-CVE-2026-1965",
      "cve": "CVE-2026-1965",
      "summary": "bad reuse of HTTP Negotiate connection",
      "published": "2026-03-11",
      "year": 2026,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Zhicheng Chen"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-1965.html"
    },
    {
      "id": "CURL-CVE-2026-3783",
      "cve": "CVE-2026-3783",
      "summary": "token leak with redirect and netrc",
      "published": "2026-03-11",
      "year": 2026,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "spectreglobalsec on hackerone"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-3783.html"
    },
    {
      "id": "CURL-CVE-2026-3784",
      "cve": "CVE-2026-3784",
      "summary": "wrong proxy connection reuse with credentials",
      "published": "2026-03-11",
      "year": 2026,
      "quarter": 1,
      "severity": "low",
      "finder_names": [
        "Muhamad Arga Reksapati (HackerOne: nobcoder)"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-3784.html"
    },
    {
      "id": "CURL-CVE-2026-3805",
      "cve": "CVE-2026-3805",
      "summary": "use after free in SMB connection reuse",
      "published": "2026-03-11",
      "year": 2026,
      "quarter": 1,
      "severity": "medium",
      "finder_names": [
        "Daniel Wade"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-3805.html"
    },
    {
      "id": "CURL-CVE-2026-4873",
      "cve": "CVE-2026-4873",
      "summary": "connection reuse ignores TLS requirement",
      "published": "2026-04-29",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Arkadi Vainbrand"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-4873.html"
    },
    {
      "id": "CURL-CVE-2026-5545",
      "cve": "CVE-2026-5545",
      "summary": "wrong reuse of HTTP Negotiate connection",
      "published": "2026-04-29",
      "year": 2026,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Quac Tran and Ngoc Hieu"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-5545.html"
    },
    {
      "id": "CURL-CVE-2026-5773",
      "cve": "CVE-2026-5773",
      "summary": "wrong reuse of SMB connection",
      "published": "2026-04-29",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Osama Hamad"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-5773.html"
    },
    {
      "id": "CURL-CVE-2026-6253",
      "cve": "CVE-2026-6253",
      "summary": "proxy credentials leak over redirect-to proxy",
      "published": "2026-04-29",
      "year": 2026,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Dwij Mehta (O2 Lab, Texas A&M University)"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-6253.html"
    },
    {
      "id": "CURL-CVE-2026-6276",
      "cve": "CVE-2026-6276",
      "summary": "stale custom cookie host causes cookie leak",
      "published": "2026-04-29",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Muhamad Arga Reksapati"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-6276.html"
    },
    {
      "id": "CURL-CVE-2026-6429",
      "cve": "CVE-2026-6429",
      "summary": "netrc credential leak with reused proxy connection",
      "published": "2026-04-29",
      "year": 2026,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Muhamad Arga Reksapati"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-6429.html"
    },
    {
      "id": "CURL-CVE-2026-7009",
      "cve": "CVE-2026-7009",
      "summary": "OCSP stapling bypass with Apple SecTrust",
      "published": "2026-04-29",
      "year": 2026,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Carlos Carrillo"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-7009.html"
    },
    {
      "id": "CURL-CVE-2026-7168",
      "cve": "CVE-2026-7168",
      "summary": "cross-proxy Digest auth state leak",
      "published": "2026-04-29",
      "year": 2026,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Muhamad Arga Reksapati"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-7168.html"
    },
    {
      "id": "CURL-CVE-2026-10536",
      "cve": "CVE-2026-10536",
      "summary": "HTTP/2 stream-dependency tree UAF",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Joshua Rogers (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-10536.html"
    },
    {
      "id": "CURL-CVE-2026-11352",
      "cve": "CVE-2026-11352",
      "summary": "QUIC zero-length UDP datagrams busy-loop",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "vectorqueue on hackerone (AntAISecurityLab)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "AntAISecurityLab"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-11352.html"
    },
    {
      "id": "CURL-CVE-2026-11564",
      "cve": "CVE-2026-11564",
      "summary": "Native CA trust persist",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Filipe Casal of Trail of Bits in collaboration with OpenAI"
      ],
      "attribution_band": "explicit_ai_marker",
      "attribution_markers": [
        "OpenAI collaboration"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-11564.html"
    },
    {
      "id": "CURL-CVE-2026-11586",
      "cve": "CVE-2026-11586",
      "summary": "WS Auto-PONG memory exhaustion",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "evergarden1123 on hackerone (AntAISecurityLab)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "AntAISecurityLab"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-11586.html"
    },
    {
      "id": "CURL-CVE-2026-11856",
      "cve": "CVE-2026-11856",
      "summary": "cross-origin Digest auth state leak",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "jjchuck on hackerone"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-11856.html"
    },
    {
      "id": "CURL-CVE-2026-12064",
      "cve": "CVE-2026-12064",
      "summary": "proto-default skips SSH verification",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "alienowo on hackerone (AntAISecurityLab)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "AntAISecurityLab"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-12064.html"
    },
    {
      "id": "CURL-CVE-2026-8286",
      "cve": "CVE-2026-8286",
      "summary": "wrong STARTTLS connection reuse",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Andrew Nesbitt (powered by Mythos)"
      ],
      "attribution_band": "explicit_ai_marker",
      "attribution_markers": [
        "Mythos",
        "powered by"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-8286.html"
    },
    {
      "id": "CURL-CVE-2026-8458",
      "cve": "CVE-2026-8458",
      "summary": "wrong reuse for different services",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Muhamad Arga Reksapati"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-8458.html"
    },
    {
      "id": "CURL-CVE-2026-8924",
      "cve": "CVE-2026-8924",
      "summary": "trailing dot domain super cookie",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "vegagent on hackerone"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-8924.html"
    },
    {
      "id": "CURL-CVE-2026-8925",
      "cve": "CVE-2026-8925",
      "summary": "SASL double-free",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Joshua Rogers (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-8925.html"
    },
    {
      "id": "CURL-CVE-2026-8926",
      "cve": "CVE-2026-8926",
      "summary": "password leak with netrc and user in URL",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Joshua Rogers (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-8926.html"
    },
    {
      "id": "CURL-CVE-2026-8927",
      "cve": "CVE-2026-8927",
      "summary": "env-set cross-proxy Digest auth state leak",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Ady Elouej"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-8927.html"
    },
    {
      "id": "CURL-CVE-2026-8932",
      "cve": "CVE-2026-8932",
      "summary": "incomplete mTLS config matching in conn reuse",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Joshua Rogers (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-8932.html"
    },
    {
      "id": "CURL-CVE-2026-9079",
      "cve": "CVE-2026-9079",
      "summary": "stale proxy password leak",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "medium",
      "finder_names": [
        "Guannan Wang",
        "Zhanpeng Liu",
        "Jiashuo Liang",
        "Guancheng Li"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-9079.html"
    },
    {
      "id": "CURL-CVE-2026-9080",
      "cve": "CVE-2026-9080",
      "summary": "UAF after pause in socket callback",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Joshua Rogers (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-9080.html"
    },
    {
      "id": "CURL-CVE-2026-9545",
      "cve": "CVE-2026-9545",
      "summary": "exposing HTTP/3 early data",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Eunsoo Kim (Autonomous Code Security team at Microsoft)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Autonomous Code Security"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-9545.html"
    },
    {
      "id": "CURL-CVE-2026-9546",
      "cve": "CVE-2026-9546",
      "summary": "sending old referer",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "renjian on hackerone"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-9546.html"
    },
    {
      "id": "CURL-CVE-2026-9547",
      "cve": "CVE-2026-9547",
      "summary": "SSH improper host validation",
      "published": "2026-06-24",
      "year": 2026,
      "quarter": 2,
      "severity": "low",
      "finder_names": [
        "Joshua Rogers (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-9547.html"
    },
    {
      "id": "CURL-CVE-2026-13608",
      "cve": "CVE-2026-13608",
      "summary": "OpenLDAP SASL authentication bypass",
      "published": "2026-09-02",
      "year": 2026,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Eunsoo Kim (Autonomous Code Security team at Microsoft)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Autonomous Code Security"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-13608.html"
    },
    {
      "id": "CURL-CVE-2026-18924",
      "cve": "CVE-2026-18924",
      "summary": "HTTP/2 server push UAF",
      "published": "2026-09-02",
      "year": 2026,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Stephan Zeisberg (Security Research Labs)"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-18924.html"
    },
    {
      "id": "CURL-CVE-2026-19931",
      "cve": "CVE-2026-19931",
      "summary": "Negotiate ambient user conn reuse",
      "published": "2026-09-02",
      "year": 2026,
      "quarter": 3,
      "severity": "medium",
      "finder_names": [
        "Martin Dukek"
      ],
      "attribution_band": "other_or_unmarked",
      "attribution_markers": [],
      "source_url": "https://curl.se/docs/CVE-2026-19931.html"
    },
    {
      "id": "CURL-CVE-2026-80229",
      "cve": "CVE-2026-80229",
      "summary": "OpenSSL provider use-after-free",
      "published": "2026-09-02",
      "year": 2026,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Stanislav Fort (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-80229.html"
    },
    {
      "id": "CURL-CVE-2026-80230",
      "cve": "CVE-2026-80230",
      "summary": "OpenSSL pinning bypass",
      "published": "2026-09-02",
      "year": 2026,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Stanislav Fort (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-80230.html"
    },
    {
      "id": "CURL-CVE-2026-80231",
      "cve": "CVE-2026-80231",
      "summary": "native CA store conn reuse",
      "published": "2026-09-02",
      "year": 2026,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Stanislav Fort (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-80231.html"
    },
    {
      "id": "CURL-CVE-2026-80255",
      "cve": "CVE-2026-80255",
      "summary": "secure cookie attribute bypass with tab",
      "published": "2026-09-02",
      "year": 2026,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Stanislav Fort (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-80255.html"
    },
    {
      "id": "CURL-CVE-2026-82208",
      "cve": "CVE-2026-82208",
      "summary": "wolfSSL CA-cache hit overrides callback",
      "published": "2026-09-02",
      "year": 2026,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Stanislav Fort (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-82208.html"
    },
    {
      "id": "CURL-CVE-2026-82209",
      "cve": "CVE-2026-82209",
      "summary": "domain-scoped PSL domain cookie",
      "published": "2026-09-02",
      "year": 2026,
      "quarter": 3,
      "severity": "low",
      "finder_names": [
        "Stanislav Fort (Aisle Research)"
      ],
      "attribution_band": "ai_affiliation_only",
      "attribution_markers": [
        "Aisle Research"
      ],
      "source_url": "https://curl.se/docs/CVE-2026-82209.html"
    }
  ]
}
