Updated: 2026-02-27 01:37:54.829935
Description:
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if an application sets up multiple concurrent transfers, the last one that sets the ciphers will accidentally control the set used by all transfers. In a worst-case scenario, this weakens transport security significantly.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | MEDIUM | 4.3 |
| CVSS Version 3.x | MEDIUM | 5.3 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| AlmaLinux 9.2 ESU | curl | 7.76.1 | 5.3 | MEDIUM | Ignored | 2023-11-08 04:08:05 | Deprioritize: This issue only occurs when libcurl is built with the Windows-only Schannel TLS backen... | |
| CentOS 6 ELS | mysql | 5.1.73 | 5.3 | MEDIUM | Ignored | 2022-04-19 21:50:23 | Ignored due to low severity | |
| CentOS 8.4 ELS | curl | 7.61.1 | 5.3 | MEDIUM | Not Vulnerable | 2022-04-19 21:49:47 | CVE-2021-22897 only triggers when libcurl 7.61.0–7.76.1 is built with the Windows-only Schannel TL... | |
| CentOS 8.4 ELS | mysql | 8.0.26 | 5.3 | MEDIUM | Ignored | 2022-07-18 11:43:15 | CVE-2021-22897 only triggers when libcurl 7.61.0–7.76.1 is built with the Windows-only Schannel TL... | |
| CentOS 8.5 ELS | mysql | 8.0.26 | 5.3 | MEDIUM | Ignored | 2022-07-18 11:43:15 | Ignored due to low severity | |
| CentOS 8.5 ELS | curl | 7.61.1 | 5.3 | MEDIUM | Ignored | 2022-04-19 21:49:47 | Ignored due to low severity | |
| CloudLinux 6 ELS | mysql | 5.1.73 | 5.3 | MEDIUM | Ignored | 2022-04-19 21:50:23 | Ignored due to low severity | |
| Debian 10 ELS | curl | 7.64.0 | 5.3 | MEDIUM | Ignored | 2025-10-11 00:23:04 | Ignored due to low severity | |
| Oracle Linux 6 ELS | mysql | 5.1.73 | 5.3 | MEDIUM | Ignored | 2022-04-19 21:50:23 | Ignored due to low severity | |
| Ubuntu 16.04 ELS | mysql-5.7 | 5.7.33-0 | 5.3 | MEDIUM | Ignored | 2022-04-19 21:50:23 | Ignored due to low severity |