Download curl from curl.se!
Release presentation
Numbers
the 272nd release
5 changes
63 days (total: 10,155)
391 bugfixes (total: 13,376)
758 commits (total: 37,486)
0 new public libcurl function (total: 100)
0 new curl_easy_setopt() option (total: 308)
0 new curl command line option (total: 273)
69 contributors, 36 new (total: 3,571)
37 authors, 14 new (total: 1,430)
6 security fixes (total: 176)
Security
This time there is no less than six separate vulnerabilities announced.
- CVE-2025-13034: skipping pinning check for HTTP/3 with GnuTLS
- CVE-2025-14017: broken TLS options for threaded LDAPS
- CVE-2025-14524: bearer token leak on cross-protocol redirect
- CVE-2025-14819: OpenSSL partial chain store policy bypass
- CVE-2025-15079: libssh global knownhost override
- CVE-2025-15224: libssh key passphrase bypass without agent set
Changes
There are a few this time, mostly around dropping support for various dependencies:
- drop support for VS2008 (Windows)
- drop Windows CE / CeGCC support
- drop support for GnuTLS < 3.6.5
- gnutls: implement CURLOPT_CAINFO_BLOB
- openssl: bump minimum OpenSSL version to 3.0.0
Bugfixes
See the release presentation video for a walk-through of some of the most important/interesting fixes done for this release, or go check out the full list in the changelog.
