Vulnerability record · CVE-2019-5436 · published 28 May 2019
CVE-2019-5436: libcurl TFTP heap buffer overflow in receiving code
Haxx · Libcurl
libcurl versions 7.19.4 through 7.64.1 contain a heap buffer overflow in the TFTP receiving code. A malformed or oversized TFTP response can corrupt heap memory, causing a denial of service or potentially arbitrary code execution in the context of the process using libcurl.
Description
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high confidentiality, integrity and availability impact and a very high EPSS percentile, though exploitation requires a TFTP path and is not known to be actively exploited.
What it is
libcurl versions 7.19.4 through 7.64.1 contain a heap buffer overflow in the TFTP receiving code. A malformed or oversized TFTP response can corrupt heap memory, causing a denial of service or potentially arbitrary code execution in the context of the process using libcurl.
Impact
An attacker controlling a TFTP server or able to inject TFTP responses can crash the client or, with heap grooming, execute arbitrary code with the privileges of the libcurl-using process.
Attack surface
Reached over the network via a TFTP transfer initiated by an application using libcurl; the CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), reflecting the attacker's position relative to the vulnerable component rather than a remote unauthenticated path.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented; EPSS is high (0.49739, 98.8th percentile), and the vendor advisory is tagged Exploit, indicating public exploit information exists.
What to do
- Upgrade libcurl to a version after 7.64.1 that contains the fix, or apply the vendor patch referenced in the curl advisory.
- Update dependent distributions and products (openSUSE Leap, Fedora, Debian, F5, NetApp, Oracle MySQL and support tools) to their patched releases.
- Disable or avoid TFTP transfers in applications using libcurl where TFTP is not required.
- Restrict outbound and inbound TFTP (UDP 69) traffic to trusted hosts to limit exposure to malicious TFTP servers.
Detection
- Monitor for crashes or abnormal termination in processes that use libcurl for TFTP transfers.
- Alert on unexpected TFTP (UDP 69) traffic from hosts that should not use TFTP.
- Track libcurl versions in deployed software and flag any still in the 7.19.4 through 7.64.1 range.
- Review application logs for TFTP transfer errors or malformed response handling around the time of process faults.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-5436 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-5436), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.