CVE Database
/

CVE-2022-22576

Back to search

CVE-2022-22576

Published: May 26, 2022

Modified: May 27, 2026

PUBLISHED

Description

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

VendorProductVersions

n/a

https://github.com/curl/curl

affected
Fixed in curl 7.83.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now