Skip to content
Curl Vulnerability Allows Unauthorized Access via IPFS URLs

Curl Vulnerability Allows Unauthorized Access via IPFS URLs

First seen 16 Sep 2026, 19:58 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 22:55 UTC
  • Curl's vulnerability allows crafted IPFS URLs to escape gateway namespaces.
  • Exploitation requires specific conditions, including authenticated gateway access.
  • Curl's security team classified the issue as informative, not a critical vulnerability.

A researcher disclosed a vulnerability in curl's handling of IPFS and IPNS URLs that allows crafted URLs to escape the configured gateway namespace. This issue affects curl versions starting from 8.5.0, including 8.22.0. By exploiting this flaw, an attacker could potentially cause curl to request sensitive paths on the same server, such as '/admin/config', while retaining authentication headers. The exploitation requires specific conditions, including the application accepting attacker-controlled URLs and using curl through an authenticated gateway. Curl's security team classified the report as informative rather than a critical vulnerability, emphasizing that the gateway must enforce its own access controls. A proposed fix has been submitted, but the vulnerability remains unclassified as a security flaw in curl itself. Users are advised to validate IPFS and IPNS URLs before passing them to authenticated gateways.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-14
Vulnerability reported to HackerOne
A researcher submitted a report detailing a flaw in curl's URL handling for IPFS and IPNS.
Redpacketsecurity
2026-09-15
First article published
Redpacketsecurity published an article detailing the vulnerability and its implications.
Redpacketsecurity
2026-09-16
Second article published
A follow-up article reiterated the vulnerability details and included a proposed fix.
Redpacketsecurity

More articles in this cluster (2)