CVE-2022-42915 - CVE House
Back to Database
Status published Unknown CVE-2022-42915

curl before 7.86.0 has a double free. If curl is...

Vulnerability Description

curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol through. An HTTP proxy might refuse this request (HTTP proxies often only allow outgoing connections to specific port numbers, like 443 for HTTPS) and instead return a non-200 status code to the client. Due to flaws in the error/cleanup handling, this could trigger a double free in curl if one of the following schemes were used in the URL for the transfer: dict, gopher, gophers, ldap, ldaps, rtmp, rtmps, or telnet. The earliest affected version is 7.77.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-42915

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

curl, fedora, h300s firmware, h500s firmware, h700s firmware, h410s firmware, ontap 9, macos, universal forwarder
Vulnerable Versions:
7.77.0, 35, 36, 37, 12.0.0, 13.0, 8.2.0, 9.0.0, 9.1.0

Timeline

Official Publish: October 29th, 2022
Last Modified: May 7th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.