CVE-2016-8625: Haxx Curl

High severity, CVSS 7.5. EPSS: 4.3% chance of exploitation in the next 30 days.

curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.

Affected products

  • Haxx Curl: before 7.51.0 (fixed in 7.51.0)

Published 2018-08-01. Last modified 2026-06-17.