Description
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.
Published: 2022-06-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-3085-1 curl security update
Debian DSA Debian DSA DSA-5197-1 curl security update
Ubuntu USN Ubuntu USN USN-5412-1 curl vulnerabilities
Ubuntu USN Ubuntu USN USN-5499-1 curl vulnerabilities
History

Thu, 16 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Debian Debian Linux
Haxx Curl
Netapp Clustered Data Ontap H300s H300s Firmware H410s H410s Firmware H500s H500s Firmware H700s H700s Firmware Hci Bootstrap Os Hci Compute Node Solidfire\, Enterprise Sds \& Hci Storage Node Solidfire \& Hci Management Node
Redhat Jboss Core Services
Splunk Universal Forwarder
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-04-16T14:03:56.482Z

Reserved: 2022-03-23T00:00:00.000Z

Link: CVE-2022-27781

cve-icon Vulnrichment

Updated: 2024-08-03T05:33:00.192Z

cve-icon NVD

Status : Modified

Published: 2022-06-02T14:15:44.467

Modified: 2026-04-16T15:16:47.947

Link: CVE-2022-27781

cve-icon Redhat

Severity : Low

Publid Date: 2022-05-11T00:00:00Z

Links: CVE-2022-27781 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses