Vulnerability Intelligence Report
CVE-2022-32206
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.
No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
Exploitability:2.9
Impact Score:3.6
EPSS Probability:31.97%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-770 ↗Allocation of Resources Without Limits or Throttling (CWE-770)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| haxx | curl | all |
| fedoraproject | fedora | 35 |
| debian | debian_linux | 10.0, 11.0 |
| netapp | clustered_data_ontap | all |
| netapp | element_software | all |
| netapp | hci_management_node | all |
| netapp | solidfire | all |
| netapp | hci_compute_node | all |
| netapp | bootstrap_os | all |
| netapp | h300s | all |
| netapp | h300s_firmware | all |
| netapp | h500s | all |
| netapp | h500s_firmware | all |
| netapp | h700s | all |
| netapp | h700s_firmware | all |
| netapp | h410s | all |
| netapp | h410s_firmware | all |
| siemens | scalance_sc622-2c | all |
| siemens | scalance_sc622-2c_firmware | all |
| siemens | scalance_sc626-2c | all |
| siemens | scalance_sc626-2c_firmware | all |
| siemens | scalance_sc632-2c_firmware | all |
| siemens | scalance_sc632-2c | all |
| siemens | scalance_sc636-2c_firmware | all |
| siemens | scalance_sc636-2c | all |
| siemens | scalance_sc642-2c_firmware | all |
| siemens | scalance_sc642-2c | all |
| siemens | scalance_sc646-2c_firmware | all |
| siemens | scalance_sc646-2c | all |
| splunk | universal_forwarder | 9.1.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
31.970%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | HackerOne · Bug Bounty Provider · USA |
| Reserved | 2022-06-01T00:00:00 |
| Published | 2022-07-07T00:00:00 |
| Last Updated | 2025-05-05T16:16:54 |
Community Chatter & Buzz