CVE-2019-5443: Haxx Curl
High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
Affected products
- Haxx Curl: up to and including 7.65.1
- Netapp Oncommand Insight: affected versions not specified
- Netapp Oncommand Unified Manager: from 7.3; from 9.5
- Netapp Oncommand Workflow Automation: affected versions not specified
- Netapp Snapcenter: affected versions not specified
- Oracle Enterprise Manager Ops Center: version 12.3.3 only; version 12.4.0 only
- Oracle HTTP Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle MySQL Server: from 5.0.0, up to and including 5.7.27; from 8.0.0, up to and including 8.0.17
- Oracle OSS Support Tools: version 20.0 only
Published 2019-07-02. Last modified 2026-06-17.