libcurl provides the CURLOPT_CERTINFO option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.
{
"license": "CC-BY-4.0",
"sources": [
{
"published": "2022-06-02T14:15:44.467Z",
"modified": "2026-04-16T15:16:47.947Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2022-27781",
"imported": "2026-05-02T08:39:45.230Z",
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27781",
"database_specific": {
"status": "Modified"
},
"id": "CVE-2022-27781"
}
]
}