CVE-2022-27781
7.5 HIGHlibcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain....
Published: 2022-06-02 · Last updated: 2026-05-27
Severity and scoring
- CVSS
- 7.5 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE
- CWE-400, CWE-835
Affected products
| Vendor | Product |
|---|---|
| debian | clustered_data_ontap, curl, debian_linux |
| haxx | clustered_data_ontap, curl, debian_linux |
| netapp | clustered_data_ontap, curl, debian_linux |
| splunk | clustered_data_ontap, curl, debian_linux |
Description
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2022-27781
- [Exploit reference]https://hackerone.com/reports/1555441
- [Other]https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- [Other]https://security.gentoo.org/glsa/202212-01
- [Other]https://security.netapp.com/advisory/ntap-20220609-0009/
- [Other]https://www.debian.org/security/2022/dsa-5197
- [Exploit reference]https://hackerone.com/reports/1555441
- [Other]https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
- [Other]https://security.gentoo.org/glsa/202212-01
- [Other]https://security.netapp.com/advisory/ntap-20220609-0009/
- [Other]https://www.debian.org/security/2022/dsa-5197
- [Exploit reference]https://hackerone.com/reports/1555441
Related CVEs
Same vendor
- CVE-2026-49975 — Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP ... (7.5 HIGH)
- CVE-2026-20240 — In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9... (6.5 MEDIUM)
- CVE-2026-20239 — In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, ... (7.5 HIGH)
- CVE-2026-20238 — In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidentia... (6.5 MEDIUM)
- CVE-2026-31431 — In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly r... (7.8 HIGH)
Same CWE
- CVE-2026-48733 — ImageMagick is free and open-source software used for editing and manipulating digital images (4.7 MEDIUM)
- CVE-2026-47734 — Dulwich is a pure-Python implementation of the Git file formats and protocols (5.7 MEDIUM)
- CVE-2026-46521 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.5 MEDIUM)
- CVE-2026-46689 — Kanidm is an identity management platform
- CVE-2026-46679 — libp2p is a JavaScript Implementation of libp2p networking stack (7.5 HIGH)