CVE-2017-1000101: Haxx Curl
Medium severity, CVSS 6.5. EPSS: 3.9% chance of exploitation in the next 30 days.
curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfers. In the globbing function that parses the numerical range, there was an omission that made curl read a byte beyond the end of the URL if given a carefully crafted, or just wrongly written, URL. The URL is stored in a heap based buffer, so it could then be made to wrongly read something else instead of crashing. An example of a URL that triggers the flaw would be `http://ur%20[0-60000000000000000000`.
Affected products
- Haxx Curl: version 7.4.1 only; version 7.35.0 only; version 7.36.0 only; version 7.37.0 only; version 7.37.1 only; version 7.38.0 only; …
Published 2017-10-05. Last modified 2026-06-17.