CVE detail
CVE-2014-2522 — CVE-2014-2522
Published 2014-04-18 · Modified 2026-06-17 · Vendor haxx · Product curl · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0258
EPSS probability
exploitation probability, 30d
84.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References