Search

Items tagged with: CURL


#curl


#curl 8.18.0 has been released. This release fixes 2 medium and 4 low level vulnerabilities:
- CVE-2025-13034: No QUIC certificate pinning with GnuTLS curl.se/docs/CVE-2025-13034.ht…
- CVE-2025-14017: broken TLS options for threaded LDAPS curl.se/docs/CVE-2025-14017.ht…
- CVE-2025-14524: bearer token leak on cross-protocol redirect curl.se/docs/CVE-2025-14524.ht…
- CVE-2025-14819: OpenSSL partial chain store policy bypass curl.se/docs/CVE-2025-14819.ht…
- CVE-2025-15079: libssh global knownhost override curl.se/docs/CVE-2025-15079.ht…
- CVE-2025-15224: libssh key passphrase bypass without agent set curl.se/docs/CVE-2025-15224.ht…

I discovered the last 2 vulnerabilities.

Download curl 8.18.0 from curl.se/download.html

#vulnerabilityresearch #vulnerability #cybersecurity #infosec


#curl


#curl 8.18.0 has been released

daniel.haxx.se/blog/2026/01/07…

#curl


#curl


As always, I will live-stream a #curl release presentation at 10:00 CET (09:00 UTC) tomorrow on my twitch channel: twitch.tv/curlhacker
#curl


The list of top #curl sponsors remains the exact same release after release...
#curl


I spend a ridiculous amount of my time on #curl security these days. Because I think that's my responsibility.

something something open source sustainability

#curl


buckle up and prepare for an unload of *six* CVEs against #curl getting published tomorrow, severity low and medium
#curl


The year's 6th day just started and we just clocked in our 8th hackerone report on #curl for the year.

This doesn't work.

#curl


less than 24 hours to the next #curl release...
#curl


#curl


on the fourth day of the year and we have already disclosed 6 Hackerone reports against #curl

This can only end one way.

#curl


#curl


First day of new year: two #curl vulnerability reports received. Both identified real bugs, neither is a security problem.
#curl


#curl


#curl


26 years ago, on December 28 1999, we migrated the main #curl source code from self-hosted to Sourceforge.

It was the new hot thing. Imagine the idea of a dedicated service devoted to nothing but hosting code!

We then kept the code there for ten years (on CVS). A period when the distributed version control systems really exploded.

#curl


No strcpy either.

daniel.haxx.se/blog/2025/12/29…

#curl

#curl


#curl hackerone update: one more vulnerability was confirmed legit and we have six pending CVEs now.

Only one of the submitted issues remains in triage but I'm advocating closing as N/A.

#curl


I'm submitting lovingly hand-crafted 100% organic reports to #curl #hackerone


I’ve heard #curl is a thing among Fediverse inhabitants. Will this help me get accepted to your tribe?
#curl


One right doesn't fix 100 wrongs. I'm happy for you and for #curl, but this doesn't change my opinion about #github and #microsoft in the slightest.


Not sure, I know there was this one time when the employees got to vote for projects to sponsor and #curl was one of them.
#curl


Number of hackerone reports on #curl doubled since last year
#curl


I spent many hours yesterday debunking another hackerone report against #curl.

It's such a good sigh of relief when the ultimate conclusion is that it is not a vulnerability. (disclosed soon of course)

#curl


GitHub is a top sponsor of #curl. They make a real difference. Can you say the same about whoever you work for?
#curl


@bagder should make phonecovers for #curl

  • Yes (0%, 0 votes)
  • Absolutely (0%, 0 votes)
  • Absolut! (0%, 0 votes)
  • Where to I buy it (100%, 1 vote)
  • Fan också! (0%, 0 votes)
1 voter. Poll end: 1 week ago


Probably old news but my mind is always blown by all the stuff #curl can do. I had zero idea that curl has a —form argument that lets you simulate filling out a form, complete with a file upload. Let me automate a super annoying task for a friend with a dead simple bash script.
#curl


#curl


#curl @cpu


#curl


Microsoft: „1 engineer, 1 month, 1 million lines of code“

That would mean @bagder
rewriting 5 #curl projects into Rust in a month.

Microsoft revising the „rewrite over a weekend“ meme to it actually taking them 6 days. For a person they have not hired yet. With tools they still have to invent.

If you are a MS customer, you‘d better start putting more money into Copilot right away!

theregister.com/2025/12/24/mic…