URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into
saving the output file outside of the current directory without the user
explicitly asking for it.
This flaw only affects the wcurl command line tool.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Curl wcurl
Haxx Haxx curl |
|
| CPEs | cpe:2.3:a:curl:wcurl:*:*:*:*:*:*:*:* cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Curl wcurl
Haxx Haxx curl |
Thu, 26 Feb 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Curl
Curl curl |
|
| Vendors & Products |
Curl
Curl curl |
Thu, 26 Feb 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 25 Feb 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
Wed, 25 Feb 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 25 Feb 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool. | |
| Title | wcurl path traversal with percent-encoded slashes | |
| References |
|
Status: PUBLISHED
Assigner: curl
Published: 2026-02-25T07:20:47.012Z
Updated: 2026-02-25T18:53:58.252Z
Reserved: 2025-10-09T13:50:54.563Z
Link: CVE-2025-11563
Updated: 2026-02-25T07:24:31.792Z
Status : Analyzed
Published: 2026-02-25T08:16:18.337
Modified: 2026-02-26T20:06:37.450
Link: CVE-2025-11563