{"id":"GHSA-3vpc-4p9p-47hc","summary":"curl_cffi bundles a version of libcurl affected by High Severity vulnerability","details":"### Summary\ncurl_cffi is potentially affected by High Severity vulnerability (CVE-2023-38545) in libcurl\u003c8.4.0\n\n### Details\nHIGH severity vulnerability in curl and libcurl: [announcement](https://github.com/curl/curl/discussions/12026#discussioncomment-7195548)\nDetails are still unknown, but seems it will be a major issue as it's advertised by curl devs as \"_probably the worst curl security flaw in a long time_\".\nA patched version (8.4.0) and details will be published around 06:00 UTC on October 11.\ncurl_cffi wheels on PyPI ship with libcurl 7.84.0\n\n### PoC\n[https://inspector.pypi.io/project/curl-cffi/0.5.10b2/packages/56/ae/eb7d39ad234f1f44650b910757d5aa696feff413d327c8328223ce78cb76/curl_cffi-0.5.10b2-cp37-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl/curl_cffi/include/curl/curlver.h](https://inspector.pypi.io/project/curl-cffi/0.5.10b2/packages/56/ae/eb7d39ad234f1f44650b910757d5aa696feff413d327c8328223ce78cb76/curl_cffi-0.5.10b2-cp37-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl/curl_cffi/include/curl/curlver.h)\n\n### Resolution\n\nVersions after 0.7 bundles with `libcurl\u003e=8.5`, which is not affected by this issue.\n","modified":"2024-12-02T05:46:31.709173Z","published":"2024-10-22T18:15:17Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-10-22T18:15:17Z","nvd_published_at":null,"cwe_ids":["CWE-1395"]},"references":[{"type":"WEB","url":"https://github.com/lexiforest/curl_cffi/security/advisories/GHSA-3vpc-4p9p-47hc"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7xw9-w465-6x42"},{"type":"PACKAGE","url":"https://github.com/lexiforest/curl_cffi"}],"affected":[{"package":{"name":"curl-cffi","ecosystem":"PyPI","purl":"pkg:pypi/curl-cffi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.0b6"}]}],"versions":["0.1.5","0.2.0","0.2.1","0.2.4","0.2.5","0.3.0","0.3.1","0.3.2","0.3.7","0.3.8","0.4.0","0.5.0","0.5.1","0.5.10","0.5.10b1","0.5.10b2","0.5.10b3","0.5.10b4","0.5.10b5","0.5.2","0.5.3","0.5.4","0.5.5","0.5.6","0.5.7","0.5.9","0.5.9b1","0.5.9b2","0.5.9b3","0.5.9b4","0.5.9b5","0.5.9b6","0.6.0","0.6.0b2","0.6.0b4","0.6.0b7","0.6.0b9","0.6.1","0.6.2","0.6.3","0.6.3b1","0.6.4","0.7.0b4"],"database_specific":{"last_known_affected_version_range":"\u003c= 0.6.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-3vpc-4p9p-47hc/GHSA-3vpc-4p9p-47hc.json"}}],"schema_version":"1.9.0"}