CVE-2017-8816: Debian Linux

Critical severity, CVSS 9.8. EPSS: 8.5% chance of exploitation in the next 30 days.

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Haxx Curl: after 7.36.0, up to and including 7.56.1
  • Haxx Libcurl: from 7.36.0, up to and including 7.56.1

Published 2017-11-29. Last modified 2026-06-17.