An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
{ "binaries": [ { "binary_version": "7.68.0-1ubuntu2.10", "binary_name": "curl" }, { "binary_version": "7.68.0-1ubuntu2.10", "binary_name": "libcurl3-gnutls" }, { "binary_version": "7.68.0-1ubuntu2.10", "binary_name": "libcurl3-nss" }, { "binary_version": "7.68.0-1ubuntu2.10", "binary_name": "libcurl4" }, { "binary_version": "7.68.0-1ubuntu2.10", "binary_name": "libcurl4-gnutls-dev" }, { "binary_version": "7.68.0-1ubuntu2.10", "binary_name": "libcurl4-nss-dev" }, { "binary_version": "7.68.0-1ubuntu2.10", "binary_name": "libcurl4-openssl-dev" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "7.81.0-1ubuntu1.1", "binary_name": "curl" }, { "binary_version": "7.81.0-1ubuntu1.1", "binary_name": "libcurl3-gnutls" }, { "binary_version": "7.81.0-1ubuntu1.1", "binary_name": "libcurl3-nss" }, { "binary_version": "7.81.0-1ubuntu1.1", "binary_name": "libcurl4" }, { "binary_version": "7.81.0-1ubuntu1.1", "binary_name": "libcurl4-gnutls-dev" }, { "binary_version": "7.81.0-1ubuntu1.1", "binary_name": "libcurl4-nss-dev" }, { "binary_version": "7.81.0-1ubuntu1.1", "binary_name": "libcurl4-openssl-dev" } ], "availability": "No subscription required" }