CURL-CVE-2018-1000005

Source
https://curl.se/docs/CVE-2018-1000005.html
Import Source
https://curl.se/docs/CURL-CVE-2018-1000005.json
JSON Data
https://api.osv.dev/v1/vulns/CURL-CVE-2018-1000005
Aliases
Published
2018-01-24T08:00:00Z
Modified
2026-05-27T02:29:11Z
Summary
HTTP/2 trailer out-of-bounds read
Details

libcurl contains an out bounds read in code handling HTTP/2 trailers.

It was reported that reading an HTTP/2 trailer could mess up future trailers since the stored size was one byte less than required.

The problem is that the code that creates HTTP/1-like headers from the HTTP/2 trailer data once appended a string like ":" to the target buffer, while this was recently changed to ": " (a space was added after the colon) but the associated math was not updated correspondingly.

When accessed, the data is read out of bounds and causes either a crash or that the (too large) data gets passed to the libcurl callback. This might lead to a denial-of-service situation or an information disclosure if someone has a service that echoes back or uses the trailers for something.

Database specific
{
    "CWE":  {
        "desc":  "Buffer Over-read",
        "id":  "CWE-126"
    },
    "URL":  "https://curl.se/docs/CVE-2018-1000005.json",
    "affects":  "both",
    "last_affected":  "7.57.0",
    "package":  "curl",
    "severity":  "Low",
    "www":  "https://curl.se/docs/CVE-2018-1000005.html"
}
Credits
    • Zhouyihai Ding - FINDER
    • Zhouyihai Ding - REMEDIATION_DEVELOPER
    • Ray Satiro - OTHER

Affected packages

Git / github.com/curl/curl.git

Affected ranges

Type
SEMVER
Events
Introduced
7.49.0
Fixed
7.58.0
Type
GIT
Repo
https://github.com/curl/curl.git
Events

Affected versions

7.*
7.49.0
7.49.1
7.50.0
7.50.1
7.50.2
7.50.3
7.51.0
7.52.0
7.52.1
7.53.0
7.53.1
7.54.0
7.54.1
7.55.0
7.55.1
7.56.0
7.56.1
7.57.0
Other
curl-7_49_0
curl-7_49_1
curl-7_50_0
curl-7_50_1
curl-7_50_2
curl-7_50_3
curl-7_51_0
curl-7_52_0
curl-7_52_1
curl-7_53_0
curl-7_53_1
curl-7_54_0
curl-7_54_1
curl-7_55_0
curl-7_55_1
curl-7_56_0
curl-7_56_1
curl-7_57_0

Database specific

source
"https://curl.se/docs/CURL-CVE-2018-1000005.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "282594126888140028228277749074138099553",
                "40991569800935917858892231272272988584",
                "95792618963566449240292544714322976924",
                "197448932819711430286793144722352352410"
            ],
            "threshold":  0.9
        },
        "id":  "CURL-CVE-2018-1000005-71fc75cd",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/curl/curl.git/commit/fa3dbb9a147488a2943bda809c66fc497efe06cb",
        "target":  {
            "file":  "lib/http2.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "67385459130250674587968461156705047700",
            "length":  2561
        },
        "id":  "CURL-CVE-2018-1000005-d7fb97d0",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/curl/curl.git/commit/fa3dbb9a147488a2943bda809c66fc497efe06cb",
        "target":  {
            "file":  "lib/http2.c",
            "function":  "on_header"
        }
    }
]
vanir_signatures_modified
"2026-05-27T02:29:11Z"