PT-2016-7530 · Curl+3 · Curl+3

Fernando Muã±Oz

·

Published

2016-11-02

·

Updated

2026-05-18

·

CVE-2016-8624

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions curl versions prior to 7.51.0
Description The issue arises when the host name part of a URL ends with a # character, causing curl to incorrectly parse the authority component of the URL. This could lead to curl connecting to a different host, potentially resulting in security implications. For instance, if an RFC-compliant URL parser is used to check for allowed domains before requesting them with curl, the incorrect parsing could allow access to unauthorized domains. The problem is not limited to a specific protocol scheme.
Recommendations For versions prior to 7.51.0, update to version 7.51.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of URLs with a # character at the end of the host name part until the update is applied. Restrict access to URLs that could potentially exploit this issue to minimize the risk of unauthorized connections.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2231
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2016-8624
DLA-711-1
DSA-3705-1
MGASA-2018-0053
OPENSUSE-SU-2016_2768-1
OPENSUSE-SU-2024:10303-1
RHSA-2018:3558
SUSE-SU-2016:2699-1
SUSE-SU-2016:2700-1
SUSE-SU-2016:2714-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-3123-1

Affected Products

Alt Linux
Suse
Ubuntu
Curl