Search

Items tagged with: Curl


added a median plot to the average #curl source code complexity graph
#curl


It's about sustainability too. #curl is a small project. We cannot spend multiple hours every day arguing with people who want money for having found what is perhaps a bug - but often is not even that.

It drains us. It drowns us.

Onward and upward!

#curl


Shld I submit a #hackerone submission for #curl, identifying hackerone as a DoS attack vector for the project, recommending depreciation?


We are at *twenty* hackerone submissions for #curl so far this year. Zero of them a confirmed vulnerability.
#curl


It is our moral imperative to consider the "real world" and actual users when assessing the possible security impact of a reported #curl issue. If we deem that there is likely to be zero affected users, then we do more damage than good by insisting on doing the security dance for the issue.

Then we end up with a severity level that is below LOW, and then we treat it as a bug instead. For the good of mankind.

#curl


To be frank: the report quality on Hackerone is so low by now that the #curl team decided to make CVEs based only on the coolness of the reporter‘s username.

💁🏻‍♂️😌

#curl


On the morning of the 13th day of the year we have received *checks notes* 13 #curl vulnerability reports on Hackerone this year.

None a confirmed vulnerability.

#curl


Working on #curl‘s rate limiting again today. It‘s a fun challenge to get this „right“.

Just a few users of this feature, though. Like Steam, Roku and Netflix. That I know of, at least.

Do you use rate limiting transfers? Do you know anyone besides #curl offering this?

#curl


The latest #curl update will now properly report long transfer times when sending data to Mars.
#curl


Augment (which gave the #curl project free access) is changing pricing (again) in what seems to be a 10x increase.

Augment pricing changes from ‚messages‘ (number of answer which you control) to ‚credit‘ (which is effort controlled by Augment).

And this is probably still not enough to cover their real costs, not even speaking of profit.

Wherever you stand on the LLM debate, don‘t become dependant on those companies. Their business model sucks.

theregister.com/2025/10/15/aug…

#curl


#curl


In this latest #curl release, we are now three persons having our names on >10,000 lines of product code when doing git blame. @icing, @vsz and myself.

10 separate people have their names on 1000+ lines.


#curl


#curl 8.18.0 has been released. This release fixes 2 medium and 4 low level vulnerabilities:
- CVE-2025-13034: No QUIC certificate pinning with GnuTLS curl.se/docs/CVE-2025-13034.ht…
- CVE-2025-14017: broken TLS options for threaded LDAPS curl.se/docs/CVE-2025-14017.ht…
- CVE-2025-14524: bearer token leak on cross-protocol redirect curl.se/docs/CVE-2025-14524.ht…
- CVE-2025-14819: OpenSSL partial chain store policy bypass curl.se/docs/CVE-2025-14819.ht…
- CVE-2025-15079: libssh global knownhost override curl.se/docs/CVE-2025-15079.ht…
- CVE-2025-15224: libssh key passphrase bypass without agent set curl.se/docs/CVE-2025-15224.ht…

I discovered the last 2 vulnerabilities.

Download curl 8.18.0 from curl.se/download.html

#vulnerabilityresearch #vulnerability #cybersecurity #infosec


#curl


#curl 8.18.0 has been released

daniel.haxx.se/blog/2026/01/07…

#curl


#curl


As always, I will live-stream a #curl release presentation at 10:00 CET (09:00 UTC) tomorrow on my twitch channel: twitch.tv/curlhacker
#curl


The list of top #curl sponsors remains the exact same release after release...
#curl


I spend a ridiculous amount of my time on #curl security these days. Because I think that's my responsibility.

something something open source sustainability

#curl


buckle up and prepare for an unload of *six* CVEs against #curl getting published tomorrow, severity low and medium
#curl


The year's 6th day just started and we just clocked in our 8th hackerone report on #curl for the year.

This doesn't work.

#curl


less than 24 hours to the next #curl release...
#curl


#curl


on the fourth day of the year and we have already disclosed 6 Hackerone reports against #curl

This can only end one way.

#curl


#curl


First day of new year: two #curl vulnerability reports received. Both identified real bugs, neither is a security problem.
#curl


#curl


#curl


26 years ago, on December 28 1999, we migrated the main #curl source code from self-hosted to Sourceforge.

It was the new hot thing. Imagine the idea of a dedicated service devoted to nothing but hosting code!

We then kept the code there for ten years (on CVS). A period when the distributed version control systems really exploded.

#curl


No strcpy either.

daniel.haxx.se/blog/2025/12/29…

#curl

#curl


#curl hackerone update: one more vulnerability was confirmed legit and we have six pending CVEs now.

Only one of the submitted issues remains in triage but I'm advocating closing as N/A.

#curl


I'm submitting lovingly hand-crafted 100% organic reports to #curl #hackerone


I’ve heard #curl is a thing among Fediverse inhabitants. Will this help me get accepted to your tribe?
#curl


One right doesn't fix 100 wrongs. I'm happy for you and for #curl, but this doesn't change my opinion about #github and #microsoft in the slightest.


Not sure, I know there was this one time when the employees got to vote for projects to sponsor and #curl was one of them.
#curl


Number of hackerone reports on #curl doubled since last year
#curl