Back to search
CVE-2022-27782
Published: Jun 1, 2022
Modified: May 27, 2026
PUBLISHED
Description
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.
| Vendor | Product | Versions |
|---|---|---|
n/a | https://github.com/curl/curl | affected Fixed in 7.83.1 |
Weaknesses (CWE)
References
DSA-5197
vendor-advisory
GLSA-202212-01
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now