Get real-time updates on Telegram
CVE-2021-22901: curl from 7.75.0 (inclusive), through 7.76.1 (inclusive); +26 more affected products
CVE-2021-22901. CVSS 3.1 base score 8.1 (HIGH, NVD). EPSS 0.60122 (percentile 0.99116), scored 2026-10-08.
Affected technology
curl · from 7.75.0 (inclusive), through 7.76.1 (inclusive)
haxx
communications cloud native core binding support function · 1.11.0
oracle
communications cloud native core network function cloud native environment · 1.10.0
oracle
communications cloud native core network repository function · 1.15.0
oracle
communications cloud native core network repository function · 1.15.1
oracle
communications cloud native core network slice selection function · 1.8.0
oracle
communications cloud native core service communication proxy · 1.15.0
oracle
essbase · before 11.1.2.4.047 (exclusive)
oracle
essbase · from 21.0 (inclusive), before 21.3 (exclusive)
oracle
mysql server · through 5.7.34 (inclusive)
oracle
mysql server · from 8.0.0 (inclusive), through 8.0.25 (inclusive)
oracle
active iq unified manager · Version not applicable in the source CPE
netapp
cloud backup · Version not applicable in the source CPE
netapp
oncommand insight · Version not applicable in the source CPE
netapp
oncommand workflow automation · Version not applicable in the source CPE
netapp
snapcenter · Version not applicable in the source CPE
netapp
solidfire, enterprise sds & hci storage node · Version not applicable in the source CPE
netapp
solidfire & hci management node · Version not applicable in the source CPE
netapp
solidfire baseboard management controller firmware · Version not applicable in the source CPE
netapp
hci compute node firmware · Version not applicable in the source CPE
netapp
h300e firmware · Version not applicable in the source CPE
netapp
h300s firmware · Version not applicable in the source CPE
netapp
h410s firmware · Version not applicable in the source CPE
netapp
h500e firmware · Version not applicable in the source CPE
netapp
h500s firmware · Version not applicable in the source CPE
netapp
h700e firmware · Version not applicable in the source CPE
netapp
h700s firmware · Version not applicable in the source CPE
netapp
sinec infrastructure network services · before 1.0.1.1 (exclusive)
siemens
universal forwarder · from 8.2.0 (inclusive), before 8.2.12 (exclusive)
splunk
universal forwarder · from 9.0.0 (inclusive), before 9.0.6 (exclusive)
splunk
universal forwarder · 9.1.0
splunk
https://github.com/curl/curl · 7.75.0 through 7.76.1
Vendor not specified by the source
Description’s affected range: through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection
Component: Not specified by the source
Function: will, pointer
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
The source reports that an attacker could run code remotely under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 8.1/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-416
- CCR priority
- 47.4 /100 (P3)
- CVSS 3.1
- 8.1 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.60122 · percentile 0.99116 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2021-22901.html