CVE-2014-2522: Haxx Curl

Medium severity, CVSS 4.0. EPSS: 2.6% chance of exploitation in the next 30 days.

curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.

Affected products

  • Haxx Curl: version 7.27.0 only; version 7.28.0 only; version 7.28.1 only; version 7.29.0 only; version 7.30.0 only; version 7.31.0 only; …
  • Haxx Libcurl: version 7.27.0 only; version 7.28.0 only; version 7.28.1 only; version 7.29.0 only; version 7.30.0 only; version 7.31.0 only; …

Published 2014-04-18. Last modified 2026-06-17.