Multiple CVEs Affect curl Due to Chained HTTP Compression Vulnerabilities
First seen 21 Feb 2026, 04:19 UTC
•
•43
Export
Article Content
Browse articles
CVE-2022-32206 and CVE-2023-23916 expose vulnerabilities in curl versions prior to 7.84.0 and 7.88.0, respectively. Both vulnerabilities allow a malicious server to exploit unbounded or improperly capped 'chained' HTTP compression algorithms, potentially leading to a 'malloc bomb' that consumes excessive heap memory. Users of affected versions are at risk of out-of-memory errors.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2022-07-07
CVE-2022-32206 published
2023-02-23
CVE-2023-23916 published
2026-02-18
Article published detailing CVE-2023-23916
2026-02-21
Article published detailing CVE-2022-32206
More articles in this cluster
Continue Reading
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
GhostShell Malware Targets Ukraine's UAV and Defense Supply Chain
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
UAT-7810 Expands Malware Arsenal to Enhance ORB Network
Sandworm Hackers Use Fake Job Interviews to Deploy Trojanized VPN Client