- What is the curl CNA?
- curl is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 26 CVE records since 2024.
- How many CVEs has curl published?
- curl has published 26 CVE records, including 25 in the last two years.
- What is curl's CVE data quality grade?
- RadicalNotion.AI grades curl's CVE data quality as F, with an overall completeness score of 57.7%. This reflects how consistently its CVE records include vendor (100%), product (100%), CVSS (0%), and CWE (30.8%) information.
- What products does curl publish CVEs for?
- curl most frequently publishes CVEs for curl, azl3 curl 8.11.1-9 on Azure Linux 3.0, azl3 curl 8.11.1-6 on Azure Linux 3.0, h300s firmware, azl3 cmake 3.30.3-14 on Azure Linux 3.0.
- Which vendors does curl cover?
- curl publishes CVEs across 1 distinct vendors, most often haxx, curl, Microsoft, netapp, apple.
- Is curl actively publishing CVEs?
- curl is currently active, based on 25 CVEs in the last two years.
- How many critical CVEs has curl published?
- curl has published 8 critical-severity CVEs and 18 high-severity CVEs.
- Are any of curl's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- No. None of curl's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- What are the most common weakness types in curl's CVEs?
- curl's CVEs most often map to these CWE weakness types: CWE-295 (Improper Certificate Validation), CWE-297 (Improper Validation of Certificate with Host Mismatch), CWE-305 (Authentication Bypass by Primary Weakness), CWE-436 (Interpretation Conflict).
- How does curl rank among CNAs?
- By total CVE volume, curl ranks #224 of 370 CNAs, and it reports more complete CVE records than 12% of all CNAs.