CVE-2016-8620: Haxx Curl

Critical severity, CVSS 9.8. EPSS: 4.7% chance of exploitation in the next 30 days.

The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.

Affected products

  • Haxx Curl: before 7.51.0 (fixed in 7.51.0)

Published 2018-08-01. Last modified 2026-06-17.