Search
Items tagged with: Curl
It's about sustainability too. #curl is a small project. We cannot spend multiple hours every day arguing with people who want money for having found what is perhaps a bug - but often is not even that.
It drains us. It drowns us.
Onward and upward!
It is our moral imperative to consider the "real world" and actual users when assessing the possible security impact of a reported #curl issue. If we deem that there is likely to be zero affected users, then we do more damage than good by insisting on doing the security dance for the issue.
Then we end up with a severity level that is below LOW, and then we treat it as a bug instead. For the good of mankind.
To be frank: the report quality on Hackerone is so low by now that the #curl team decided to make CVEs based only on the coolness of the reporter‘s username.
💁🏻♂️😌
On the morning of the 13th day of the year we have received *checks notes* 13 #curl vulnerability reports on Hackerone this year.
None a confirmed vulnerability.
Augment (which gave the #curl project free access) is changing pricing (again) in what seems to be a 10x increase.
Augment pricing changes from ‚messages‘ (number of answer which you control) to ‚credit‘ (which is effort controlled by Augment).
And this is probably still not enough to cover their real costs, not even speaking of profit.
Wherever you stand on the LLM debate, don‘t become dependant on those companies. Their business model sucks.
theregister.com/2025/10/15/aug…
AI startup Augment scraps 'unsustainable' pricing, users say new model is 10x worse
: Second huge increase in six months sees some devs heading for the exitTim Anderson (The Register)
Copyright without years
Like so many other software projects the curl project has copyright mentions at the top of almost every file in the source code repository. Like Copyright (C) 1998 - 2022, Daniel Stenberg ...daniel.haxx.se
#curl 8.18.0 with Daniel Stenberg
curl 8.18.0 with Daniel Stenberg
Daniel talks about the six(!) new security advisories, the changes and the most important bugfixes from the curl 8.18.0 release.YouTube
#curl 8.18.0 has been released. This release fixes 2 medium and 4 low level vulnerabilities:
- CVE-2025-13034: No QUIC certificate pinning with GnuTLS curl.se/docs/CVE-2025-13034.ht…
- CVE-2025-14017: broken TLS options for threaded LDAPS curl.se/docs/CVE-2025-14017.ht…
- CVE-2025-14524: bearer token leak on cross-protocol redirect curl.se/docs/CVE-2025-14524.ht…
- CVE-2025-14819: OpenSSL partial chain store policy bypass curl.se/docs/CVE-2025-14819.ht…
- CVE-2025-15079: libssh global knownhost override curl.se/docs/CVE-2025-15079.ht…
- CVE-2025-15224: libssh key passphrase bypass without agent set curl.se/docs/CVE-2025-15224.ht…
I discovered the last 2 vulnerabilities.
Download curl 8.18.0 from curl.se/download.html
#vulnerabilityresearch #vulnerability #cybersecurity #infosec
#curl 8.18.0 has been released
daniel.haxx.se/blog/2026/01/07…
curl 8.18.0
Download curl from curl.se! Release presentation On January 7 2026, at 10:00 CET (09:00 UTC), there is a live-streamed release presentation of curl 8.18.0 done on twitch. The YouTube recording will be made available afterwards.daniel.haxx.se
6,000 curl stickers
I am heading to FOSDEM again at the end of January. I go there every year and I have learned that there is a really sticker-happy audience there. The last few times I have been there, I have given away several thousands of curl stickers.daniel.haxx.se
curlhacker - Twitch
I'm Daniel Stenberg, maintainer and lead developer in the curl project. I stream curl related stuff. Release presentations, curl development and related topics.Twitch
I spend a ridiculous amount of my time on #curl security these days. Because I think that's my responsibility.
something something open source sustainability
The year's 6th day just started and we just clocked in our 8th hackerone report on #curl for the year.
This doesn't work.
Fixed missing space in cookie header when using multiple -b flags by pojomi · Pull Request #20184 · curl/curl
Summary When using multiple -b flags, the Cookie header was missing a space after the semicolon separator. Bug behavior curl -b 'a=b' -b 'c=d' https://google.com/ Produced: Cookie: ...GitHub
on the fourth day of the year and we have already disclosed 6 Hackerone reports against #curl
This can only end one way.
docs: add a note about --compressed to note about binary output by tstoeckler · Pull Request #20168 · curl/curl
Follow-up from #19867 Instead of modifying the binary output warning directly, this just adds a note to the docs as requested.GitHub
digest: fix OWS and escaped quote handling by trxvorr · Pull Request #20102 · curl/curl
The migration to the strparse API introduced regressions in Digest authentication parsing where Optional Whitespace (OWS) after commas was not skipped, and escaped quotes in values were not correct...GitHub
26 years ago, on December 28 1999, we migrated the main #curl source code from self-hosted to Sourceforge.
It was the new hot thing. Imagine the idea of a dedicated service devoted to nothing but hosting code!
We then kept the code there for ten years (on CVS). A period when the distributed version control systems really exploded.
No strcpy either.
daniel.haxx.se/blog/2025/12/29…
#curl
no strcpy either
Some time ago I mentioned that we went through the curl source code and eventually got rid of all strncpy() calls. strncpy() is a weird function with a crappy API. It might not null terminate the destination and it pads the target buffer with zeroes.daniel.haxx.se
#curl hackerone update: one more vulnerability was confirmed legit and we have six pending CVEs now.
Only one of the submitted issues remains in triage but I'm advocating closing as N/A.