gmane.comp.web.curl.announce archive
388 archived articles, newest first (page 1 of 4). Latest articles →
[SECURITY ADVISORIES] for curl 8.21.0
Wed, 24 Jun 2026 08:08:57 +0200 (CEST)[RELEASE] curl 8.21.0
Wed, 24 Jun 2026 08:05:00 +0200 (CEST)[ADVISORY] curl: CVE-2026-7168: cross-proxy Digest auth state leak
Wed, 29 Apr 2026 08:01:29 +0200 (CEST)[ADVISORY] curl: CVE-2026-7009: OCSP stapling bypass with Apple SecTrust
Wed, 29 Apr 2026 08:01:23 +0200 (CEST)[ADVISORY] curl: CVE-2026-6429: netrc credential leak with reused proxy connection
Wed, 29 Apr 2026 08:01:19 +0200 (CEST)[ADVISORY] curl: CVE-2026-6276: stale custom cookie host causes cookie leak
Wed, 29 Apr 2026 08:01:15 +0200 (CEST)[ADVISORY] curl: CVE-2026-6253: proxy credentials leak over redirect-to proxy
Wed, 29 Apr 2026 08:01:10 +0200 (CEST)[ADVISORY] curl: CVE-2026-5773: wrong reuse of SMB connection
Wed, 29 Apr 2026 08:01:05 +0200 (CEST)[ADVISORY] curl: CVE-2026-5545: wrong reuse of HTTP Negotiate connection
Wed, 29 Apr 2026 08:01:00 +0200 (CEST)[ADVISORY] curl: CVE-2026-4873: connection reuse ignores TLS requirement
Wed, 29 Apr 2026 08:00:52 +0200 (CEST)[RELEASE] curl 8.20.0
Wed, 29 Apr 2026 08:00:33 +0200 (CEST)[ADVISORY] curl: CVE-2026-3805: use after free in SMB connection reuse
Wed, 11 Mar 2026 07:54:50 +0100 (CET)[ADVISORY] curl: CVE-2026-3784: wrong proxy connection reuse with credentials
Wed, 11 Mar 2026 07:54:47 +0100 (CET)[ADVISORY] curl: CVE-2026-3783: token leak with redirect and netrc
Wed, 11 Mar 2026 07:54:44 +0100 (CET)[ADVISORY] curl: CVE-2026-1965: bad reuse of HTTP Negotiate connection
Wed, 11 Mar 2026 07:54:38 +0100 (CET)[RELEASE] curl 8.19.0
Wed, 11 Mar 2026 07:54:29 +0100 (CET)[rc] curl 8.19.0-rc3
Fri, 27 Feb 2026 09:43:46 +0100 (CET)[rc] curl 8.19.0-rc2
Sat, 21 Feb 2026 11:59:46 +0100 (CET)[release candidate] curl 8.19.0-rc1
Thu, 12 Feb 2026 09:30:55 +0100 (CET)[ADVISORY] curl CVE-2025-15224: libssh key passphrase bypass without agent set
Wed, 7 Jan 2026 08:09:43 +0100 (CET)[ADVISORY] curl CVE-2025-15079: libssh global knownhost override
Wed, 7 Jan 2026 08:09:40 +0100 (CET)[ADVISORY] curl CVE-2025-14819: OpenSSL partial chain store policy bypass
Wed, 7 Jan 2026 08:09:36 +0100 (CET)[ADVISORY] curl CVE-2025-14524: bearer token leak on cross-protocol redirect
Wed, 7 Jan 2026 08:09:30 +0100 (CET)[ADVISORY] curl CVE-2025-14017: broken TLS options for threaded LDAPS
Wed, 7 Jan 2026 08:09:18 +0100 (CET)[ADVISORY] curl CVE-2025-13034: No QUIC certificate pinning with GnuTLS
Wed, 7 Jan 2026 08:09:12 +0100 (CET)[RELEASE] curl 8.18.0
Wed, 7 Jan 2026 08:09:00 +0100 (CET)Release candidate 3: curl 8.18.0-rc3
Sat, 27 Dec 2025 10:27:56 +0100 (CET)Release candidate 2: curl 8.18.0-rc2
Mon, 15 Dec 2025 07:56:40 +0100 (CET)Release candidate 1: curl 8.18.0-rc1 and FEATURE FREEZE
Sat, 6 Dec 2025 14:32:42 +0100 (CET)[SECURITY ADVISORY] curl: missing SFTP host verification with wolfSSH
Wed, 5 Nov 2025 08:14:12 +0100 (CET)[RELEASE] curl 8.17.0
Wed, 5 Nov 2025 08:12:26 +0100 (CET)[SECURITY ADVISORY] wcurl path traversal with percent-encoded slashes
Tue, 4 Nov 2025 09:42:02 +0100 (CET)Release candidate 3: curl 8.17.0-rc3
Wed, 29 Oct 2025 07:50:56 +0100 (CET)Release candidate 2: curl 8.17.0-rc2
Mon, 20 Oct 2025 09:00:19 +0200 (CEST)Release candidate 1: curl 8.17.0-rc1
Sat, 11 Oct 2025 15:52:55 +0200 (CEST)[SECURITY ADVISORY] curl: CVE-2025-10148: predictable WebSocket mask
Wed, 10 Sep 2025 07:54:30 +0200 (CEST)[SECURITY ADVISORY] curl: CVE-2025-9086: Out of bounds read for cookie path
Wed, 10 Sep 2025 07:53:14 +0200 (CEST)[RELEASE] curl 8.16.0
Wed, 10 Sep 2025 07:51:12 +0200 (CEST)Release candidate 3: curl 8.16.0-rc3
Wed, 3 Sep 2025 08:45:53 +0200 (CEST)Release candidate 2: curl 8.16.0-rc2
Mon, 25 Aug 2025 22:59:10 +0200 (CEST)Release candidate 1: curl 8.16.0-rc1
Mon, 18 Aug 2025 07:59:57 +0200 (CEST)[RELEASE] curl 8.15.0
Wed, 16 Jul 2025 08:34:48 +0200 (CEST)Release candidate 3: curl 8.15.0-rc3
Wed, 9 Jul 2025 13:40:50 +0200 (CEST)Release candidate 2: curl 8.15.0-rc2
Mon, 30 Jun 2025 13:39:24 +0200 (CEST)Release candidate 1: curl 8.15.0-rc1
Sat, 21 Jun 2025 11:55:36 +0200 (CEST)[SECURITY AVISORY] curl: CVE-2025-5399: WebSocket endless loop
Wed, 4 Jun 2025 07:52:47 +0200 (CEST)[RELEASE] curl and libcurl 8.14.1
Wed, 4 Jun 2025 07:51:54 +0200 (CEST)[SECURITY ADVISORY] curl: No QUIC certificate pinning with wolfSSL
Wed, 28 May 2025 07:49:44 +0200 (CEST)[SECURITY ADVISORY] curl: QUIC certificate check skip with wolfSSL
Wed, 28 May 2025 07:49:41 +0200 (CEST)[RELEASE] curl and libcurl 8.14.0
Wed, 28 May 2025 07:49:32 +0200 (CEST)Release candidate 3: curl 8.14.0-rc3
Wed, 21 May 2025 08:02:12 +0200 (CEST)Release candidate 2: curl 8.14.0-rc2
Mon, 12 May 2025 07:52:54 +0200 (CEST)Release candidate 1: curl 8.14.0-rc1
Thu, 1 May 2025 22:38:27 +0200 (CEST)[RELEASE] curl 8.13.0
Wed, 2 Apr 2025 07:53:38 +0200 (CEST)Release candidate 3: curl 8.13.0-rc3
Wed, 26 Mar 2025 08:03:01 +0100 (CET)Release candidate 2: curl 8.13.0-rc2
Mon, 17 Mar 2025 16:30:25 +0100 (CET)Release candidate 1: curl 8.13.0-rc1
Sat, 8 Mar 2025 10:27:35 +0100 (CET)[RELEASE] curl 8.12.1
Thu, 13 Feb 2025 08:27:01 +0100 (CET)[SECURITY ADVISORY] curl: CVE-2025-0725: gzip integer overflow
Wed, 5 Feb 2025 09:21:42 +0100 (CET)[SECURITY ADVISORY] curl: CVE-2025-0665: eventfd double close
Wed, 5 Feb 2025 09:21:39 +0100 (CET)[SECURITY ADVISORY] curl: CVE-2025-0167: netrc and default credential leak
Wed, 5 Feb 2025 09:21:35 +0100 (CET)[RELEASE] curl 8.12.0
Wed, 5 Feb 2025 09:20:18 +0100 (CET)[SECURITY ADVISORY] curl: CVE-2024-11053: netrc and redirect credential leak
Wed, 11 Dec 2024 08:27:18 +0100 (CET)[RELEASE] curl 8.11.1
Wed, 11 Dec 2024 08:25:55 +0100 (CET)[SECURITY ADVISTORY] curl: CVE-2024-9681 HSTS subdomain overwrites parent cache entry
Wed, 6 Nov 2024 08:25:04 +0100 (CET)[RELEASE] curl 8.11.0
Wed, 6 Nov 2024 08:23:30 +0100 (CET)[RELEASE] curl 8.10.1
Wed, 18 Sep 2024 08:10:24 +0200 (CEST)[SECURITY ADVISORY] curl: CVE-2024-8096: OCSP stapling bypass with GnuTLS
Wed, 11 Sep 2024 07:47:34 +0200 (CEST)[RELEASE] curl 8.10.0
Wed, 11 Sep 2024 07:46:33 +0200 (CEST)[SECURITY ADVISORY] curl: CVE-2024-7264 ASN.1 date parser overread
Wed, 31 Jul 2024 09:19:47 +0200 (CEST)[RELEASE] curl 8.9.1
Wed, 31 Jul 2024 09:18:49 +0200 (CEST)[SECURITY ADVISORY] curl: CVE-2024-6874: macidn punycode buffer overread
Wed, 24 Jul 2024 08:35:28 +0200 (CEST)[SECURITY ADVISORY] curl: CVE-2024-6197: freeing stack buffer in utf8asn1str
Wed, 24 Jul 2024 08:34:35 +0200 (CEST)[RELEASE] curl 8.9.0
Wed, 24 Jul 2024 08:32:31 +0200 (CEST)[RELEASE] curl 8.8.0
Wed, 22 May 2024 08:00:44 +0200 (CEST)curl user survey 2024
Tue, 14 May 2024 08:08:52 +0200 (CEST)[RELEASE] curl 8.7.1
Wed, 27 Mar 2024 09:11:45 +0100 (CET)[SECURITY ADVISORY] curl: CVE-2024-2466: TLS certificate check bypass with mbedTLS
Wed, 27 Mar 2024 07:58:12 +0100 (CET)[SECURITY ADVISORY] curl: CVE-2024-2398: HTTP/2 push headers memory-leak
Wed, 27 Mar 2024 07:58:09 +0100 (CET)[SECURITY ADVISORY] curl: CVE-2024-2379: QUIC certificate check bypass with wolfSSL
Wed, 27 Mar 2024 07:58:05 +0100 (CET)[SECURITY ADVISORY] curl: CVE-2024-2004: Usage of disabled protocol
Wed, 27 Mar 2024 07:58:00 +0100 (CET)[RELEASE] curl 8.7.0
Wed, 27 Mar 2024 07:57:52 +0100 (CET)[SECURITY ADVISORY] curl: CVE-2024-0853 : OCSP verification bypass with TLS session reuse
Wed, 31 Jan 2024 08:12:18 +0100 (CET)[RELEASE] curl 8.6.0
Wed, 31 Jan 2024 08:11:24 +0100 (CET)[SECURITY ADVISORY] curl: HSTS long file name clears contents
Wed, 6 Dec 2023 08:29:50 +0100 (CET)[SECURITY ADVISORY] curl: cookie mixed case PSL bypass
Wed, 6 Dec 2023 08:29:10 +0100 (CET)[RELEASE] curl 8.5.0
Wed, 6 Dec 2023 08:27:13 +0100 (CET)[SECURITY ADVISORY] curl: CVE-2023-38546
Wed, 11 Oct 2023 07:59:02 +0200 (CEST)[SECURITY ADVISORY] curl: CVE-2023-38545: SOCKS5 heap buffer overflow
Wed, 11 Oct 2023 07:58:42 +0200 (CEST)[RELEASE] curl 8.4.0
Wed, 11 Oct 2023 07:58:05 +0200 (CEST)CVE-2023-38039 curl: HTTP headers eat all memory
Wed, 13 Sep 2023 08:31:25 +0200 (CEST)[RELEASE] curl 8.3.0
Wed, 13 Sep 2023 08:30:22 +0200 (CEST)[RELEASE] curl and libcurl 8.2.1
Wed, 26 Jul 2023 08:19:38 +0200 (CEST)curl: fopen race condition: CVE-2023-32001
Wed, 19 Jul 2023 08:30:54 +0200 (CEST)[RELEASE] curl and libcurl 8.2.0
Wed, 19 Jul 2023 08:30:01 +0200 (CEST)Reminder: the curl and libcurl user survey 2023
Mon, 5 Jun 2023 19:30:31 +0200 (CEST)Reminder: the curl and libcurl user survey 2023
Thu, 1 Jun 2023 08:34:11 +0200 (CEST)[RELEASE] curl 8.1.2
Tue, 30 May 2023 08:39:48 +0200 (CEST)The curl and libcurl user survey 2023
Wed, 24 May 2023 23:49:50 +0200 (CEST)[RELEASE] curl 8.1.1
Tue, 23 May 2023 08:22:44 +0200 (CEST)
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.