VYPR
Medium severity5.3NVD Advisory· Published Jul 31, 2018· Updated Jun 17, 2026

CVE-2016-8624

CVE-2016-8624

Description

curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, and could instead be tricked into connecting to a different host. This may have security implications if you for example use an URL parser that follows the RFC to check for allowed domains before using curl to request them.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.