CVE-2022-32206 Details
Description
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| haxx curl | < 7.84.0 |
CPE
Remediation
| |
| fedoraproject fedora | 35 |
CPE
Remediation
| |
| debian debian linux | 10.0 11.0 |
CPE
Remediation
| |
| netapp clustered data ontap | All versions |
CPE
Remediation
| |
| netapp element software | All versions |
CPE
Remediation
| |
| netapp hci management node | All versions |
CPE
Remediation
| |
| netapp solidfire | All versions |
CPE
Remediation
| |
| netapp hci compute node | All versions |
CPE
Remediation
| |
| netapp bootstrap os | All versions |
CPE
Remediation
| |
| netapp h300s | All versions |
CPE
Remediation
| |
| netapp h300s firmware | All versions |
CPE
Remediation
| |
| netapp h500s | All versions |
CPE
Remediation
| |
| netapp h500s firmware | All versions |
CPE
Remediation
| |
| netapp h700s | All versions |
CPE
Remediation
| |
| netapp h700s firmware | All versions |
CPE
Remediation
| |
| netapp h410s | All versions |
CPE
Remediation
| |
| netapp h410s firmware | All versions |
CPE
Remediation
| |
| siemens scalance sc622-2c | All versions |
CPE
Remediation
| |
| siemens scalance sc622-2c firmware | < 3.0 |
CPE
Remediation
| |
| siemens scalance sc626-2c | All versions |
CPE
Remediation
| |
| siemens scalance sc626-2c firmware | < 3.0 |
CPE
Remediation
| |
| siemens scalance sc632-2c firmware | < 3.0 |
CPE
Remediation
| |
| siemens scalance sc632-2c | All versions |
CPE
Remediation
| |
| siemens scalance sc636-2c firmware | < 3.0 |
CPE
Remediation
| |
| siemens scalance sc636-2c | All versions |
CPE
Remediation
| |
| siemens scalance sc642-2c firmware | < 3.0 |
CPE
Remediation
| |
| siemens scalance sc642-2c | All versions |
CPE
Remediation
| |
| siemens scalance sc646-2c firmware | < 3.0 |
CPE
Remediation
| |
| siemens scalance sc646-2c | All versions |
CPE
Remediation
| |
| splunk universal forwarder | >= 8.2.0, < 8.2.12 >= 9.0.0, < 9.0.6 9.1.0 |
CPE
Remediation
| |
Change History
20 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 5, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Mar 27, 2024 | Modified Analysis | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Feb 15, 2023 | CVE Modified | [email protected] |
| Jan 5, 2023 | Modified Analysis | [email protected] |
| Dec 19, 2022 | CVE Modified | [email protected] |
| Dec 13, 2022 | CVE Modified | [email protected] |
| Dec 8, 2022 | Modified Analysis | [email protected] |
| Oct 30, 2022 | CVE Modified | [email protected] |
| Oct 27, 2022 | Modified Analysis | [email protected] |
| Oct 25, 2022 | CVE Modified | [email protected] |
| Sep 15, 2022 | CVE Modified | [email protected] |
| Aug 29, 2022 | CVE Modified | [email protected] |
| Aug 2, 2022 | CVE Modified | [email protected] |
| Jul 15, 2022 | CVE Modified | [email protected] |
| Jul 14, 2022 | Initial Analysis | [email protected] |