#curl 8.16.0 was just released:
daniel.haxx.se/blog/2025/09/10…
I will live-stream a release presentation at 10:00 CEST on twitch
curl 8.16.0
Welcome to one of the more feature-packed curl releases we have had in a while. Exactly eight weeks since we shipped 8.15.0.daniel.haxx.se
daniel:// stenberg://
in reply to daniel:// stenberg:// • • •CVE-2025-9086: Out of bounds read for cookie path
Severity: Low
curl.se/docs/CVE-2025-9086.htm…
curl - Out of bounds read for cookie path - CVE-2025-9086
curl.sedaniel:// stenberg://
in reply to daniel:// stenberg:// • • •CVE-2025-10148: predictable WebSocket mask
Severity: Low
curl.se/docs/CVE-2025-10148.ht…
curl - predictable WebSocket mask - CVE-2025-10148
curl.sedaniel:// stenberg://
in reply to daniel:// stenberg:// • • •Poolitzer
in reply to daniel:// stenberg:// • • •Cassandrich
in reply to daniel:// stenberg:// • • •Does curl have an option (command line or library interface) to forbid using cleartext protocols even when redirected?
(I.e. make the request fail rather than compromise secrecy, basically same as Firefox https-only mode.)
I thought of it because it would have prevented this from happening and it's probably what most modern users want.
daniel:// stenberg://
in reply to Cassandrich • • •daniel:// stenberg://
in reply to daniel:// stenberg:// • • •Cassandrich
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Cassandrich • • •Stefan Eissing
in reply to daniel:// stenberg:// • • •vsz
in reply to daniel:// stenberg:// • • •curl for Windows
curl.sedaniel:// stenberg:// reshared this.