CYBER CODE RED

Get real-time updates on Telegram

P3Verified

CVE-2021-22901: curl from 7.75.0 (inclusive), through 7.76.1 (inclusive); +26 more affected products

CVE-2021-22901. CVSS 3.1 base score 8.1 (HIGH, NVD). EPSS 0.60122 (percentile 0.99116), scored 2026-10-08.

Affected technology

curl · from 7.75.0 (inclusive), through 7.76.1 (inclusive)
haxx

communications cloud native core binding support function · 1.11.0
oracle

communications cloud native core network function cloud native environment · 1.10.0
oracle

communications cloud native core network repository function · 1.15.0
oracle

communications cloud native core network repository function · 1.15.1
oracle

communications cloud native core network slice selection function · 1.8.0
oracle

communications cloud native core service communication proxy · 1.15.0
oracle

essbase · before 11.1.2.4.047 (exclusive)
oracle

essbase · from 21.0 (inclusive), before 21.3 (exclusive)
oracle

mysql server · through 5.7.34 (inclusive)
oracle

mysql server · from 8.0.0 (inclusive), through 8.0.25 (inclusive)
oracle

active iq unified manager · Version not applicable in the source CPE
netapp

cloud backup · Version not applicable in the source CPE
netapp

oncommand insight · Version not applicable in the source CPE
netapp

oncommand workflow automation · Version not applicable in the source CPE
netapp

snapcenter · Version not applicable in the source CPE
netapp

solidfire, enterprise sds & hci storage node · Version not applicable in the source CPE
netapp

solidfire & hci management node · Version not applicable in the source CPE
netapp

solidfire baseboard management controller firmware · Version not applicable in the source CPE
netapp

hci compute node firmware · Version not applicable in the source CPE
netapp

h300e firmware · Version not applicable in the source CPE
netapp

h300s firmware · Version not applicable in the source CPE
netapp

h410s firmware · Version not applicable in the source CPE
netapp

h500e firmware · Version not applicable in the source CPE
netapp

h500s firmware · Version not applicable in the source CPE
netapp

h700e firmware · Version not applicable in the source CPE
netapp

h700s firmware · Version not applicable in the source CPE
netapp

sinec infrastructure network services · before 1.0.1.1 (exclusive)
siemens

universal forwarder · from 8.2.0 (inclusive), before 8.2.12 (exclusive)
splunk

universal forwarder · from 9.0.0 (inclusive), before 9.0.6 (exclusive)
splunk

universal forwarder · 9.1.0
splunk

https://github.com/curl/curl · 7.75.0 through 7.76.1
Vendor not specified by the source

Description’s affected range: through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection

Component: Not specified by the source
Function: will, pointer

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could run code remotely under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 8.1/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-416
CCR priority
47.4 /100 (P3)
CVSS 3.1
8.1 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.60122 · percentile 0.99116 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2021-22901.html