CVE-2014-0139: Haxx Curl

Medium severity, CVSS 5.8. EPSS: 4.4% chance of exploitation in the next 30 days.

cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

Affected products

  • Haxx Curl: version 7.10.6 only; version 7.10.7 only; version 7.10.8 only; version 7.11.0 only; version 7.11.1 only; version 7.11.2 only; …
  • Haxx Libcurl: version 7.10.6 only; version 7.10.7 only; version 7.10.8 only; version 7.11.0 only; version 7.11.1 only; version 7.11.2 only; …

Published 2014-04-15. Last modified 2026-06-17.