← Vulnerability feed

Vulnerability record · CVE-2016-8622 · published 31 July 2018

CVE-2016-8622: Haxx libcurl heap-based buffer overflow vulnerability

Haxx · Libcurl

The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return that new length in a signed 32 bit integer variable, thus the length would get either just truncated or both truncated and turned negative. That could then lead to libcurl writing outside of its heap based buffer.

9.8 CVSS 3.0 Critical EPSS 4.7% · top 8.6% CWE-122 · Heap-based buffer overflowCWE-190 · Integer overflow
9.8CVSS 3.0 base score, v2 7.5
4.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return that new length in a signed 32 bit integer variable, thus the length would get either just truncated or both truncated and turned negative. That could then lead to libcurl writing outside of its heap based buffer.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8622 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38545curl SOCKS5 proxy handshake heap buffer overflowcurl contains a heap-based out-of-bounds write (CWE-787) in the SOCKS5 proxy handshake. When a host name longer than 255 bytes is passed for proxy-si…EPSS 78%analysed9.8CVE-2019-3822Haxx libcurl stack-based buffer overflow vulnerabilitylibcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (…EPSS 13%9.8CVE-2018-14618Haxx libcurl heap-based buffer overflow vulnerabilitycurl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multipl…EPSS 11%9.8CVE-2017-8816Haxx curl integer overflow vulnerabilityThe NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow…EPSS 8.5%9.8CVE-2017-8817Haxx curl out-of-bounds read vulnerabilityThe FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application …EPSS 11%9.8CVE-2017-8818Haxx curl memory buffer overflow vulnerabilitycurl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possi…EPSS 3.8%9.8CVE-2016-7167Fedoraproject fedora integer overflow vulnerabilityMultiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.…EPSS 12%9.1CVE-2021-22945Haxx libcurl double free vulnerabilityWhen sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory a…EPSS 6.7%

Source: NIST National Vulnerability Database (record CVE-2016-8622), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.