📦 Universal Forwarder

by Splunk

🔍 What is Universal Forwarder?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-23914

CRITICAL CVSS 9.1 Feb 23, 2023

A vulnerability in curl versions before 7.88.0 causes HSTS (HTTP Strict Transport Security) to fail when processing multiple URLs sequentially on the same command line. This allows sensitive informati...

CVE-2022-32221

CRITICAL CVSS 9.8 Dec 5, 2022

This vulnerability in libcurl allows an attacker to cause memory corruption or data leakage when reusing a handle from a PUT to a POST request. Applications using libcurl for HTTP(S) transfers with re...

CVE-2022-32207

CRITICAL CVSS 9.8 Jul 7, 2022

CVE-2022-32207 is a privilege escalation vulnerability in curl versions before 7.84.0 where file permission widening occurs during atomic file operations. When curl saves cookies, alt-svc, or hsts dat...

CVE-2021-3520

CRITICAL CVSS 9.8 Jun 2, 2021

CVE-2021-3520 is an integer overflow vulnerability in the LZ4 compression library that allows attackers to trigger out-of-bounds writes by submitting crafted files. This can lead to application crashe...

CVE-2025-20298

HIGH CVSS 8.0 Jun 2, 2025

This vulnerability allows non-administrator users on Windows systems to access the Splunk Universal Forwarder installation directory and all its contents due to incorrect permissions assignment during...

CVE-2023-27533

HIGH CVSS 8.8 Mar 30, 2023

A vulnerability in curl versions before 8.0 allows attackers to inject malicious content during TELNET protocol negotiation when user input is accepted. This could lead to arbitrary code execution on ...

CVE-2023-27534

HIGH CVSS 8.8 Mar 30, 2023

A path traversal vulnerability in curl's SFTP implementation allows attackers to bypass path filtering by using specially crafted paths containing tilde characters. This affects curl versions before 8...

CVE-2022-35737

HIGH CVSS 7.5 Aug 3, 2022

This SQLite vulnerability allows array-bounds overflow when processing extremely large string arguments (billions of bytes) through certain C API functions. It affects applications using vulnerable SQ...

CVE-2022-32156

HIGH CVSS 8.1 Jun 15, 2022

Splunk Enterprise and Universal Forwarder versions before 9.0 do not validate TLS certificates by default when the CLI connects to remote Splunk instances. This allows machine-in-the-middle attackers ...

CVE-2022-27780

HIGH CVSS 7.5 Jun 2, 2022

The curl URL parser incorrectly accepts percent-encoded URL separators like '/' in hostnames, allowing attackers to bypass filters and checks by making malicious URLs appear legitimate. This affects a...

CVE-2022-27782

HIGH CVSS 7.5 Jun 2, 2022

libcurl incorrectly reuses TLS/SSH connections when security settings have changed, potentially allowing sensitive data to be transmitted over less secure connections. This affects any application usi...

CVE-2022-27775

HIGH CVSS 7.5 Jun 2, 2022

This curl vulnerability allows information disclosure when an attacker can force curl to reuse an existing IPv6 connection from the pool with a different zone identifier, potentially exposing sensitiv...

CVE-2022-27778

HIGH CVSS 8.1 Jun 2, 2022

This vulnerability in curl versions before 7.83.1 could cause the wrong file to be deleted when using the --no-clobber option with --remove-on-error. It affects systems using curl with these specific ...

CVE-2021-22926

HIGH CVSS 7.5 Aug 5, 2021

This vulnerability allows attackers to trick libcurl applications into using a malicious client certificate instead of the intended one when running in writable directories like /tmp. It affects appli...

CVE-2021-30560

HIGH CVSS 8.8 Aug 3, 2021

This is a use-after-free vulnerability in Chrome's Blink XSLT processor that allows remote attackers to potentially exploit heap corruption. Attackers can craft malicious HTML pages to trigger memory ...

CVE-2021-22901

HIGH CVSS 8.1 Jun 11, 2021

CVE-2021-22901 is a use-after-free vulnerability in curl/libcurl that allows a malicious TLS 1.3 server to potentially execute arbitrary code on the client. This affects curl clients using OpenSSL wit...