CERT-FR warns of nine curl vulnerabilities
CERT-FR advisory lists nine curl CVEs affecting versions 7.44.0 through 8.22.0 that can compromise data confidentiality, integrity, and security policy enforcement.
CERT-FR (the French national CERT) published an advisory summarizing nine vulnerabilities in the curl library affecting versions from 7.44.0 up to but not including 8.22.0. The advisory does not specify detailed technical mechanisms for each flaw but categorizes the risks as impacting data confidentiality, data integrity, and security policy bypass. No exploitation in the wild is mentioned in this bulletin.
Given curl's ubiquity as an underlying library in countless applications, operating systems, and embedded devices, organizations should identify all instances of curl within their software supply chain and update to version 8.22.0 or later as recommended by the curl project's own security bulletins referenced in the advisory. No proof-of-concept or active exploitation details are provided, and the advisory functions as a routine patch notification rather than an urgent incident report.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1108
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free