Here's a user in the wild who was bitten by the Apple "backdoor" in #curl:

github.com/curl/curl/discussio…

#curl
Unknown parent

mastodon - Link to source

daniel:// stenberg://

@callionica they are always slow - I have no secret direct channel to them. I can only use their generic product security email. But they did respond faster than two moths, it just took them this long to come to a conclusion about this particular issue.

I don't know how long it has been there. It would not surprise me if it has been there since they started building curl with libressl, several years ago. (can't recall the exact timing for that)