Security researchers at AISLE identified six new CVEs in curl and libcurl, including a vulnerability tracing back to curl 7.7 from March 2001 that allowed an existing connection to be reused even after client certificate or private key settings changed. The flaws span credential confusion, memory-safety bugs such as double-frees and use-after-free issues, and improper host validation across authentication, SSH, and HTTP/2 code paths. curl’s maintainers addressed 18 vulnerabilities in total in the release that incorporated AISLE’s findings.
