CVE-2016-8624 MEDIUM

CVE-2016-8624

Vendor The Curl Project
Product curl
Weakness CWE-20 · Input validation
Published July 31, 2018
Last update April 16, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, and could instead be tricked into connecting to a different host. This may have security implications if you for example use an URL parser that follows the RFC to check for allowed domains before using curl to request them.

Key dates

02Disclosure timeline

July 31, 2018 CVE published
April 16, 2026 Record updated