PT-2016-7531 · Curl+1 · Curl+1

Padma81

·

Published

2016-11-02

·

Updated

2026-05-18

·

CVE-2016-8625

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions curl versions prior to 7.51.0
Description The issue arises from curl's use of the outdated IDNA 2003 standard to handle International Domain Names, which may lead users to unknowingly issue network transfer requests to the wrong host. This is particularly problematic with domains using special characters, such as the German ß character, which is translated differently in IDNA 2003 and the modern IDNA 2008 standard. For instance, the domain straße.de is translated to strasse.de using IDNA 2003, but to xn--strae-oqa.de using IDNA 2008, potentially resolving to different addresses.
Recommendations For versions prior to 7.51.0, update to version 7.51.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of International Domain Names with special characters until the update is applied. Restrict access to DNS-using protocols in curl when built with libidn to minimize the risk of exploitation. Avoid using curl with libidn for domains that require IDNA 2008, such as .de domains, until the issue is resolved.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2231
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2016-8625
OPENSUSE-SU-2024:10303-1
RHSA-2018:3558

Affected Products

Alt Linux
Curl