ThreatCluster

Multiple CVEs Affect curl Due to Chained HTTP Compression Vulnerabilities

First seen 21 Feb 2026, 04:19 UTC Api.Msrc.Microsoft 43

Article Content

Browse articles
ThreatCluster

CVE-2022-32206 and CVE-2023-23916 expose vulnerabilities in curl versions prior to 7.84.0 and 7.88.0, respectively. Both vulnerabilities allow a malicious server to exploit unbounded or improperly capped 'chained' HTTP compression algorithms, potentially leading to a 'malloc bomb' that consumes excessive heap memory. Users of affected versions are at risk of out-of-memory errors.

Timeline

2022-07-07
CVE-2022-32206 published
2023-02-23
CVE-2023-23916 published
2026-02-18
Article published detailing CVE-2023-23916
2026-02-21
Article published detailing CVE-2022-32206