← Vulnerability feed

Vulnerability record · CVE-2014-0015 · published 2 February 2014

CVE-2014-0015: Haxx libcurl improper authentication vulnerability

Haxx · Libcurl

cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.

4.0 CVSS 2.0 Medium EPSS 5.6% · top 7.4% CWE-287 · Improper authentication
4.0CVSS 2.0 base score
5.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
50References
17 Jun 2026Last modified by NVD

Description

cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.

AV:N/AC:H/Au:N/C:P/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.html
http://curl.haxx.se/docs/adv_20140129.html PatchVendor Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127627.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128408.html
http://lists.opensuse.org/opensuse-updates/2014-02/msg00066.html
http://seclists.org/fulldisclosure/2014/Dec/23
http://secunia.com/advisories/56728 Vendor Advisory
http://secunia.com/advisories/56731
http://secunia.com/advisories/56734 Vendor Advisory
http://secunia.com/advisories/56912
http://secunia.com/advisories/59458
http://secunia.com/advisories/59475
http://support.apple.com/kb/HT6296
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862
http://www.debian.org/security/2014/dsa-2849
http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
http://www.securityfocus.com/archive/1/534161/100/0/threaded
http://www.securityfocus.com/bid/65270
http://www.securitytracker.com/id/1029710
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.502652
http://www.ubuntu.com/usn/USN-2097-1
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.html
http://curl.haxx.se/docs/adv_20140129.html PatchVendor Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127627.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128408.html
http://lists.opensuse.org/opensuse-updates/2014-02/msg00066.html
http://seclists.org/fulldisclosure/2014/Dec/23
http://secunia.com/advisories/56728 Vendor Advisory
http://secunia.com/advisories/56731
http://secunia.com/advisories/56734 Vendor Advisory
http://secunia.com/advisories/56912
http://secunia.com/advisories/59458
http://secunia.com/advisories/59475
http://support.apple.com/kb/HT6296
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862

Track CVE-2014-0015 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-19931Haxx curl vulnerabilityA flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is do…EPSS 0.75%9.8CVE-2026-9079Haxx curl insufficiently protected credentials vulnerabilitylibcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get …EPSS 0.58%9.8CVE-2026-8925Haxx curl double free vulnerabilityThe curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making…EPSS 1.1%9.8CVE-2026-10536Haxx curl use after free vulnerabilityA use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CUR…EPSS 0.60%9.8CVE-2026-11856Haxx curl authentication bypass by capture-replay vulnerabilitySuccessfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a diff…EPSS 0.69%9.8CVE-2023-38545curl SOCKS5 proxy handshake heap buffer overflowcurl contains a heap-based out-of-bounds write (CWE-787) in the SOCKS5 proxy handshake. When a host name longer than 255 bytes is passed for proxy-si…EPSS 78%analysed9.8CVE-2022-32221Haxx curl information exposure vulnerabilityWhen doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOP…EPSS 4.4%9.8CVE-2022-32207Haxx curl incorrect default permissions vulnerabilityWhen curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from …EPSS 7.7%

Source: NIST National Vulnerability Database (record CVE-2014-0015), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.