CVE-2019-5443: Haxx Curl

High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

Affected products

  • Haxx Curl: up to and including 7.65.1
  • Netapp Oncommand Insight: affected versions not specified
  • Netapp Oncommand Unified Manager: from 7.3; from 9.5
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Oracle Enterprise Manager Ops Center: version 12.3.3 only; version 12.4.0 only
  • Oracle HTTP Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle MySQL Server: from 5.0.0, up to and including 5.7.27; from 8.0.0, up to and including 8.0.17
  • Oracle OSS Support Tools: version 20.0 only

Published 2019-07-02. Last modified 2026-06-17.