Friendica
daniel:// stenberg://
daniel:// stenberg://

daniel:// stenberg://

bagder@mastodon.social

daniel:// stenberg://

bagder@mastodon.social
I write curl. I don't know anything.
ActivityPub
2025-09-10 12:47:26 2025-09-10 05:55:25 2025-09-10 05:55:24 8713951

daniel:// stenberg://
daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

1 day ago • •

daniel:// stenberg://

1 day ago • •


#curl 8.16.0 was just released:

daniel.haxx.se/blog/2025/09/10…

I will live-stream a release presentation at 10:00 CEST on twitch


curl 8.16.0

Welcome to one of the more feature-packed curl releases we have had in a while. Exactly eight weeks since we shipped 8.15.0.
daniel.haxx.se
#curl
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to daniel:// stenberg:// • 1 day ago • •

CVE-2025-9086: Out of bounds read for cookie path

Severity: Low

curl.se/docs/CVE-2025-9086.htm…

curl - Out of bounds read for cookie path - CVE-2025-9086

curl.se
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to daniel:// stenberg:// • 1 day ago • •

CVE-2025-10148: predictable WebSocket mask

Severity: Low

curl.se/docs/CVE-2025-10148.ht…

curl - predictable WebSocket mask - CVE-2025-10148

curl.se
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to daniel:// stenberg:// • 20 hours ago • •
oops I got the affected version range wrong for CVE-2025-10148, it has now been updated
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Poolitzer
mastodon - Link to source

Poolitzer

in reply to daniel:// stenberg:// • 1 day ago • •
uh a LLM doing a bug fix look at that
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Cassandrich
mastodon - Link to source

Cassandrich

in reply to daniel:// stenberg:// • 20 hours ago • •

Does curl have an option (command line or library interface) to forbid using cleartext protocols even when redirected?

(I.e. make the request fail rather than compromise secrecy, basically same as Firefox https-only mode.)

I thought of it because it would have prevented this from happening and it's probably what most modern users want.

  •  Languages
  •  Search Text
  •  Share via ...
in reply to Cassandrich

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Cassandrich • 20 hours ago • •
this is a vulnerability only for users using "ws://" explicitly so such users would presumably override a secure-only filter if there would be one... (which there isn't... yet)
This entry was edited (20 hours ago)
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to daniel:// stenberg:// • 20 hours ago • •
@dalias this vulnerability is mostly theoretical and really only hurts buggy proxies involved in the traffic
@Cassandrich
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Cassandrich
mastodon - Link to source

Cassandrich

in reply to daniel:// stenberg:// • 20 hours ago • •
I was talking about the http cookie OOB read bug, which presumably can be triggered when an attacker redirects you from an https url you intended to fetch to an http url on another site.
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Cassandrich

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Cassandrich • 20 hours ago • •
@dalias oops, sorry I confused them. Right, that one would be prevented if curl would by default refuse insecure connections.
@Cassandrich
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Stefan Eissing
mastodon - Link to source

Stefan Eissing

in reply to daniel:// stenberg:// • 1 day ago • •
Just read the Changes to see what we‘ve done…
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

vsz
mastodon - Link to source

vsz

in reply to daniel:// stenberg:// • 1 day ago • •
#curl binaries out at: curl.se/windows/

curl for Windows

curl.se
#curl
  •  Languages
  •  Search Text
  •  Share via ...

daniel:// stenberg:// reshared this.

⇧