VORANT. Threat Intelligence Sign in Get the full feed

CERT-FR warns of nine curl vulnerabilities

elevated vulnerability technology

CERT-FR advisory lists nine curl CVEs affecting versions 7.44.0 through 8.22.0 that can compromise data confidentiality, integrity, and security policy enforcement.

CERT-FR (the French national CERT) published an advisory summarizing nine vulnerabilities in the curl library affecting versions from 7.44.0 up to but not including 8.22.0. The advisory does not specify detailed technical mechanisms for each flaw but categorizes the risks as impacting data confidentiality, data integrity, and security policy bypass. No exploitation in the wild is mentioned in this bulletin.

Given curl's ubiquity as an underlying library in countless applications, operating systems, and embedded devices, organizations should identify all instances of curl within their software supply chain and update to version 8.22.0 or later as recommended by the curl project's own security bulletins referenced in the advisory. No proof-of-concept or active exploitation details are provided, and the advisory functions as a routine patch notification rather than an urgent incident report.

Mentioned in this report

Vulnerabilities CVE-2026-13608CVE-2026-18924CVE-2026-19931CVE-2026-80229CVE-2026-80230CVE-2026-80231CVE-2026-80255CVE-2026-82208CVE-2026-82209

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1108

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free