CVE-2015-3153: Apple Mac OS X

Medium severity, CVSS 5.0. EPSS: 7.3% chance of exploitation in the next 30 days.

The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.

Affected products

  • Apple Mac OS X: version 10.10.4 only
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 14.10 only; version 15.1 only
  • Debian Debian Linux: version 8.0 only
  • Haxx Curl: up to and including 7.42.0
  • Haxx Libcurl: up to and including 7.42.0
  • Oracle Enterprise Manager Ops Center: up to and including 12.1.3; version 12.2.0 only; version 12.2.1 only; version 12.3.0 only

Published 2015-05-01. Last modified 2026-06-17.