cvedb.io
CVE-2022-27781
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2022-06-02T14:15:44.467 · Last modified 2026-06-17T04:37:29.900

Summary

libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.

Affected products

haxx — curl

Does this affect you?

Add your gear to cvedb and we'll alert you only when haxx ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.