CURL-CVE-2016-7141

    Dashboard / Vulnerabilities / CURL-CVE-2016-7141

    CURL-CVE-2016-7141

    Published: 7 Sept 2016Last Modified: 25 Apr 2026
    Aliases:

    Summary: Incorrect reuse of client certificates

    Details: libcurl built on top of NSS (Network Security Services) incorrectly reused client certificates if a certificate from file was used for one TLS connection but no certificate set for a subsequent TLS connection. While the symptoms are similar to CVE-2016-5420 (Reusing connection with wrong client cert), this vulnerability was caused by an implementation detail of the NSS backend in libcurl, which is orthogonal to the cause of CVE-2016-5420.

    References:

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 7.19.6
    Fixed -7.50.2

    Affected versions

    7.50.1
    7.50.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CURL-CVE-2016-7141 | CVE-DB