libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN. Asking to convert a name that is exactly 256 bytes, libcurl ends up reading outside of a stack based buffer when built to use the *macidn* IDN backend. The conversion function then fills up the provided buffer exactly - but does not null terminate the string.
This flaw can lead to stack contents accidently getting returned as part of the converted string.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Aug 22, 2024 | Jul 24, 2024 |
| Debian | — | Upgrade curl | Jul 27, 2026 | Jul 27, 2026 |
| Suse | — | Upgrade libcurl4Upgrade libcurl-develUpgrade libcurl-mini4Upgrade curl-zsh-completionUpgrade curlUpgrade libcurl-devel-32bitUpgrade libcurl4-32bitUpgrade libcurl-devel-doc | Dec 5, 2025 | Sep 12, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub