Items tagged with: curl

Search

Items tagged with: curl


oldest #curl version in a bug report filed today, and we're not even at 9am yet: 7.4 years
#curl


#curl


How does #curl connect to which host when doing HTTP? First draft.
#curl


I dare to claim that few software projects, open or closed, do better, more detailed and more specific security advisories than #curl does.

If there ever is any detail around a #curl CVE you miss or you find an error in, I hope you tell us.

#curl


#curl 8.14.1 is out

daniel.haxx.se/blog/2025/06/04…

Thanks to Calvin Ruocco, Dan Fandrich, Daniel Stenberg, denandz on github, Ethan Everett, Jacob Mealey, Jeremy Drake, Jeroen Ooms, John Bampton, Kadambini Nema, Michael Kaufmann, Rasmus Melchior Jacobsen, Ray Satiro, Samuel Henrique, Stefan Eissing, Viktor Szakats, x-xiang on github, Yedaya Katsman, Yuyi Wang, z2_

#curl


#curl


If I'm going to be totally honest: implementing anything in #curl is about fourteen times easier and more fun than the thread- and object-spaghetti that is #Firefox code... But don't tell anyone I said this.


After I wrote (most of) the DoH implementation for #Firefox it was not too hard to subsequently add support for DoH in #curl.


In today's #curl git stats, we can spot that @icing has climbed to all-time committer number seven based on number of commits (665).

Number three based on number of added lines (116,415).

And yet his first commit was merged as late as November 2021. It's never too late to make an impact.

Thanks Stefan! 🏆


#curl


Are you interested in helping out to make a Network.framework SSL backend for #curl?

The Secure Transport one is going away and this could be a new way to use the native Apple system.

But code does not write itself. There is an embryo started, but it needs love.

github.com/curl/curl/pull/1750…

#curl


From the department of useless numbers:

Since the year 2000, I have committed to the #curl source git repository on 5,400 individual dates. 58% of all days since.

#curl


Did my duty for the pending #curl patch release on Wednesday. The photo.
#curl


assessing #curl security reports on a Saturday while my freshly baked rhubarb crumble pie is cooling off
#curl


surprised #user upgrading curl from an 8 years old version to a modern one: what? it requires 64bit integer types now?

So yeah, those users are still out there.

Imagine the craziness, a software in 2025 that REQUIRES a 64 bit integer type. The boldness.

And you thought #curl was conservative! 🤠


I use curl to make `()` into `{}`. 🫨

#curl

#curl


FYI: HTTP/3 support in #curl is not experimental anymore if built to use ngtcp2 + nghttp3
#curl


Referring sites for visitors to #curl's GitHub repository over the last 14 days.

Interesting I think.

#curl


#curl and its website feature no trackers, no cookies, no ads, no website analytics, no telemetry, no logs. We truly don't know you and what you do with curl - unless you tell us in our annual survey.
#curl


The #curl bug-bounty has paid 91,900 USD in reward money

For 80 confirmed security problems.

#curl


FTP is quite unique in the #curl collection of protocols due to its (weird) mandatory use of a separate TCP connection for the data transfer (and the fact that it can be setup in either direction, client to server or server to client) . It is complicated for users, for sysadmins and it is a complication in source code and internal curl TCP management as well.

So yeah, it also keeps causing us headaches to this day.

#curl


Circa five years ago the browsers dropped FTP support.

#curl still supports it. In 2024, 23% of curl users said they used FTP within the past two years.

My post from April 2020:

daniel.haxx.se/blog/2020/04/15…

#curl


#curl


#curl


#curl


it is with a hanging head we must conclude that we shipped a few quite annoying regressions yesterday and now we plan...

#curl 8.14.1 to be released on June 4, on Wednesday.

The idea is to fix as many bugs as possible before then.

May the next one be better!

#curl


How can #OpenSource and #security be interconnected?
What will be the future of funding the open source-dependent public digital infrastructure?

These and many other questions will guide the discussion of our panelists:
🔸@bagder from #cURL
🔸@melanierieback from @ros
🔸Matteo Mole from @EuropeanCyber SecurityOrganisation
🔸Nicholas Gates from @OpenForumEurope
🔸Mirko Boehm from #TheLinuxFoundation

Join the webinar : europeanopensource.academy/for…


#curl


Including the two new #curl CVEs, the share of all #curl CVEs that are "C mistakes" are now at 39.16%

A trend? A fluke? We need to give it another half-decade or so to be able to tell for sure.

(Flaws listed as "C mistakes" are vulnerabilities that we deem are likely to not have happened should we have used a memory-safe language rather than C)

#curl


#curl


The two #curl CVEs we publish today are both rated medium and affect QUIC connections when curl is built to use wolfSSL

Hiroki Kurosawa reported both and he is rewarded 2540 USD for each from the curl bug-bounty.

With these two, the total bug-bounty payout from #curl now exceeds 90,000 USD over the last few years.

curl.se/docs/bugbounty.html

(thanks to IBB for sponsoring our bug-bounty program!)

#curl


#curl 8.14.0 is here with new stuff, bugfixes and two security advisories.

Live-streamed presentation at 08:00 UTC today.

daniel.haxx.se/blog/2025/05/28…

#curl


I chatted with @bagder about #Curl and the recent #AI happenings

It's always fun talking to Daniel, and I think there's a lot of good ideas in this one, especially on how to approach AI fueled contributions that aren't slop. And even suggestions on how to deal with slop contributions :)

opensourcesecurity.io/2025/202…


#curl 8.14.0 arrives tomorrow but let me give you some numbers already now...
#curl


Had a small photo session to get some new material for the #curl release slide set for the release presentation tomorrow. Daisy the cat was not impressed.
#curl


The #curl eight week release cycle explained in a single image
#curl


When #curl turns into an evil empire, we already have the flag done.
#curl