Forum Discussion

InsightCanvas's avatar
InsightCanvas
New Member
1 month ago
Solved

libcurl vulnerabilities

Our vulnerability scanner has identified several vulnerabilities affecting the bundled libcurl.dll component included with various ODBC drivers in Microsoft Power BI Desktop. The reported vulnerabili...
  • rajendraongole1's avatar
    1 month ago

    Hi InsightCanvas - The libcurl.dll files you're seeing are bundled with third-party Simba ODBC drivers that ship with Power BI Desktop and the On-premises Data Gateway. Vulnerability scanners often flag these based on the library version, but whether a specific CVE is exploitable depends on how the driver uses the affected functionality.

     

    1. Open a Microsoft Support ticket if the issue requires an official security assessment or remediation timeline.
    2. Monitor the monthly Power BI Desktop and On-premises Data Gateway release notes for updates to bundled drivers and security fixes.
    3. Validate whether the reported CVEs are actually applicable to your deployment, as version-based scanner findings can sometimes be false positives if the vulnerable code paths are not used.

     

    https://community.fabric.microsoft.com/t5/Fabric-Updates-Blog/On-premises-data-gateway-June-2026-release/bc-p/5251347

     

    Until Microsoft publishes an official advisory or release, any timeline for updating the bundled libcurl libraries would be speculative.

     

    Hope this helps.