CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2022-32221

CVSS 9.8v3.1pub. 2022-12-05upd. 2026-02-13

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apple macOS

    OS
    Apple
    < 12.6.3
  • Debian

    OS
    Debian
    10.011.0
  • Haxx Curl

    APP
    Haxx
    < 7.86.0
  • Netapp Clustered Data Ontap

    APP
    Netapp
    all versions
  • Netapp H300s

    HW
    Netapp
    all versions
  • Netapp H300s Firmware

    OS
    Netapp
    all versions
  • Netapp H410s

    HW
    Netapp
    all versions
  • Netapp H410s Firmware

    OS
    Netapp
    all versions
  • Netapp H500s

    HW
    Netapp
    all versions
  • Netapp H500s Firmware

    OS
    Netapp
    all versions
  • Netapp H700s

    HW
    Netapp
    all versions
  • Netapp H700s Firmware

    OS
    Netapp
    all versions
  • Splunk Universal Forwarder

    APP
    Splunk
    9.1.08.2.0 – 8.2.12 (excl.)9.0.0 – 9.0.6 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product

GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)