Search

Items tagged with: CURL


I added a sentence to the #curl hackerone submission page:

"Please present your case briefly and to the point. Do not use an AI to help you blab hundreds of lines that will exhaust us to death instead of making us understand your claim."

#curl


We end the year with 6 more #curl command line options than we had last new year's eve; now at 273 in total.
#curl


#curl


*Twelve* Hackerone submissions against #curl within the last seven days.

Zero of them turned out a confirmed vulnerability.

Several of them found, reported, phrased-in-far-too-many-words and mislead by stupid word completion machines.

#curl


If your company needs #curl support for OpenSSL 1.1 in 2026, just say so and we can have you covered in no time.

OpenSSL 1 support is dropped from the regular #curl releases but is available as a commercial offer.

#curl


This is not working. The number of #hackerone report submissions for #curl in 2025 is going through the roof, while the quality is going through the floor.

And the year isn't over yet.


#curl


When you‘re low on RAM, I recommend using a recent #curl for your internet transfers.

It can shuffle gigabytes back and forth using a few MB of your memory (mostly used by openssl).

If you develop an application, you can use #libcurl to gain its benefits.

Need to shape your traffic? For example bc you run a streaming service? #libcurl does that for you for all HTTP versions.


Today, twenty-nine awesome years ago, httpget 0.2 shipped. Unfortunately, both the source and the changelog for this release have been lost in time (like tears in rain).

httpget was the precursor to what later would become #curl

The internet, and the web, was different in 1996.

#curl


Five years ago I started getting these emails about #curl from NASA. Months later we learned this probably was related to them using curl in the Mars Helicopter mission.

daniel.haxx.se/blog/2020/12/17…

#curl


#curl


#curl


#curl


#curl


With 20 days left to next #curl release

Stats so far this cycle:

Commits: 530 (total 37258)
Commit authors: 27, 9 new (total 1425)
Contributors: 52, 24 new (total 3559)
Bugfixes logged: 290 (7.99 per day)

#curl


We currently have three pending CVEs to be announced in the next #curl release (severity low + medium x 2)

All three found with AI powered tooling.

So it is happening.

#curl


Cartero looks solid!

But for a fair comparison, let's put #curl on the chart.

#curl


On this day six years ago, we learned that mr Robot curls:

daniel.haxx.se/blog/2019/12/10…

Exactly three years later, still this date, we found a #curl sighting in the movie Silk Road:

daniel.haxx.se/blog/2022/12/10…

#curl


⭐ ⭐ ⭐ ⭐ ⭐

The #curl repo on GitHub surpassed 40K stars: github.com/curl/curl

⭐ ⭐ ⭐ ⭐ ⭐

#curl


Remember the AIxCC competition? After lots of research and triaging, the conclusion has landed: not a single *real* problem was found in #curl.

My previous write-up on the rather lame injected problems they found:

daniel.haxx.se/blog/2025/10/22…

#curl


#curl


Your regular reminder that an #IPv4 address is just a 32-number, and yes, #curl accepts it as such.


#curl


#curl


Speaking day at Build Stuff. Better wear my best shirt. #curl
#curl


#curl


A new Hackerone issue was submitted for #curl and I had it closed as not applicable within four minutes. A new personal record I believe.

(It will be disclosed asap.)

#curl


Today December 4, at 18:00 CET I will talk tiny #curl. With a bird-themed slide set!

us02web.zoom.us/webinar/regist…

#curl


Reminder. #curl runs in all your devices. So I made a slide to show some of them.

(yeah, I've used and shown this slide numerous times before and I will probably do it again...)

#curl


#curl


#curl


I was wondering whether #curl somehow does its own parsing of /etc/hosts, because it does something _very_ weird, and it seems it's c-ares who is guilty
#curl


#curl