Skip to content

[GHSA-rrg6-wpjx-p5jf] The 'globbing' feature in curl before version 7.51.0 has...#7368

Open
tjuyuxinzhang wants to merge 1 commit intotjuyuxinzhang/advisory-improvement-7368from
tjuyuxinzhang-GHSA-rrg6-wpjx-p5jf
Open

[GHSA-rrg6-wpjx-p5jf] The 'globbing' feature in curl before version 7.51.0 has...#7368
tjuyuxinzhang wants to merge 1 commit intotjuyuxinzhang/advisory-improvement-7368from
tjuyuxinzhang-GHSA-rrg6-wpjx-p5jf

Conversation

@tjuyuxinzhang
Copy link
Copy Markdown

Updates

  • Affected products
  • CWEs
  • References
  • Source code location
  • Summary

Comments
The current advisory appears inaccurate in several key fields. According to the curl project’s official security advisory for CVE-2016-8620, this issue affects the curl tool globbing parser only, not the libcurl library. The official advisory classifies the issue as Medium severity, identifies the weakness as CWE-122 (Heap-based Buffer Overflow), states that affected versions are curl 7.34.0 through 7.50.3 inclusive, and that the issue was fixed in 7.51.0. The current GitHub advisory severity, CVSS vector, and CWE classification do not match the upstream curl advisory. This update aligns the advisory with the project’s official disclosure and fix reference.

@github-actions github-actions bot changed the base branch from main to tjuyuxinzhang/advisory-improvement-7368 April 12, 2026 17:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant