Loading HuntDB...

GHSA-xxw5-p895-cp2c

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.

Related CVEs

Key Information

GHSA ID
GHSA-xxw5-p895-cp2c
Published
May 4, 2022 12:27 AM
Last Modified
May 4, 2022 12:27 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 29, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.