Welcome to this new release. Get it as always from https://curl.se.
If you rather want a security-patched older release branch, stay tuned for the follow-up Rock-solid curl announcement within a few days.
Release presentation
Numbers
the 276th release
6 changes
70 days (total: 10,887)
302 bugfixes (total: 14,489)
525 commits (total: 39,608)
0 new public libcurl function (total: 100)
4 new curl_easy_setopt() option (total: 312)
4 new curl command line option (total: 278)
85 contributors, 55 new (total: 3,786)
43 authors, 29 new (total: 1,518)
9 security fixes (total: 215)
Security
Associated with this release, we publish ten new CVEs. Nine of them are for curl and libcurl, and one is for wcurl.
- CVE-2026-13608: OpenLDAP SASL authentication bypass
- CVE-2026-18924: HTTP/2 server push UAF
- CVE-2026-19931: Negotiate ambient user conn reuse
- CVE-2026-80229: OpenSSL provider use-after-free
- CVE-2026-80230: OpenSSL pinning bypass
- CVE-2026-80231: native CA store conn reuse
- CVE-2026-80255: secure cookie attribute bypass with tab
- CVE-2026-82208: wolfSSL CA-cache hit overrides callback
- CVE-2026-82209: domain-scoped PSL domain cookie
The wcurl one:
CVE-2026-80256: wcurl backslash bypass
Changes
- added support for Apple GSS Framework
- added API guards
- new RFC 9421 HTTP Message Signatures support (experimental)
- blocks NTLM fallback in SPNEGO negotiation
- dropped support for TLS-SRP
- added option to use Apple fast UDP
Coming removals
- HTTP/2 Server Push
- local crypto implementations
- NTLM
- SMB
Next
We plan the next curl release to happen at the end of October unless there are some bad regressions reported against 8.22.0.