FlawAtlas
Search the atlas
CVE-2016-8624 Moderate

invalid URL parsing with '#'

curl does not parse the authority component of the URL correctly when the host name part ends with a hash (`#`) character, and could instead be tricked into connecting to a different host. This may have security implications if you for example use a URL parser that follows the RFC to check for allowed domains before using curl to request them. Passing in `http://example.com#@evil.com/x.txt` would wrongly make curl send a request to evil.com while your browser would connect to example.com given the same URL. The problem exists for most protocol schemes.

Exploit probability 6.3%
Published November 2, 2016
Required by Not available
Last source change May 27, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

139 explicit affected versions

Unknown Unknown

271 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2016-8624

curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, and could instead be tricked into connecting to a different host. This may have security implications if you for example use an URL parser that follows the RFC to check for allowed domains before using curl to request them.

View original source
Open Source Vulnerabilities CURL-CVE-2016-8624

curl does not parse the authority component of the URL correctly when the host name part ends with a hash (`#`) character, and could instead be tricked into connecting to a different host. This may have security implications if you for example use a URL parser that follows the RFC to check for allowed domains before using curl to request them. Passing in `http://example.com#@evil.com/x.txt` would wrongly make curl send a request to evil.com while your browser would connect to example.com given the same URL. The problem exists for most protocol schemes.

View original source

05 / REFERENCES

Further evidence