cvedb.io
CVE-2022-32221
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2022-12-05T22:15:10.343 · Last modified 2026-06-17T04:46:54.347

Summary

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.

Affected products

haxx — curl

Does this affect you?

Add your gear to cvedb and we'll alert you only when haxx ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.