{"id":23736,"date":"2024-01-16T23:21:11","date_gmt":"2024-01-16T22:21:11","guid":{"rendered":"https:\/\/daniel.haxx.se\/blog\/?p=23736"},"modified":"2024-01-16T23:21:11","modified_gmt":"2024-01-16T22:21:11","slug":"curl-is-a-cna","status":"publish","type":"post","link":"https:\/\/daniel.haxx.se\/blog\/2024\/01\/16\/curl-is-a-cna\/","title":{"rendered":"curl is a CNA"},"content":{"rendered":"\n<p><a href=\"https:\/\/curl.se\/\">The curl project<\/a> has been accepted as a <a href=\"https:\/\/www.cve.org\/ProgramOrganization\/CNAs\">CVE Numbering Authority<\/a> (CNA) for vulnerabilities in all products directly made or managed by the project. If I&#8217;m counting correctly, we are the 351st CNA.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"789\" height=\"690\" src=\"https:\/\/daniel.haxx.se\/blog\/wp-content\/uploads\/2016\/05\/curl-symbol.png\" alt=\"\" class=\"wp-image-8943\" style=\"width:161px;height:auto\" srcset=\"https:\/\/daniel.haxx.se\/blog\/wp-content\/uploads\/2016\/05\/curl-symbol.png 789w, https:\/\/daniel.haxx.se\/blog\/wp-content\/uploads\/2016\/05\/curl-symbol-200x175.png 200w, https:\/\/daniel.haxx.se\/blog\/wp-content\/uploads\/2016\/05\/curl-symbol-450x394.png 450w, https:\/\/daniel.haxx.se\/blog\/wp-content\/uploads\/2016\/05\/curl-symbol-768x672.png 768w\" sizes=\"auto, (max-width: 789px) 100vw, 789px\" \/><\/figure>\n<\/div>\n\n\n<p><a href=\"https:\/\/www.cve.org\/Media\/News\/item\/news\/2024\/01\/16\/curl-Added-as-CNA\">The official announcement from Mitre<\/a> states: <em>curl is now a CVE Numbering Authority (CNA) for all products made and managed by the curl project. This includes curl, libcurl, and trurl.<\/em><\/p>\n\n\n\n<p>In plain English, this means that we will reserve and manage our own CVEs in the future directly against the CVE database with no middle man, and also that we have a scope for CVEs that is our territory: curl and libcurl. No one else can now register CVEs for our products &#8211; without involving us. (There&#8217;s an appeals process so someone can still actually file CVEs for issues even if we say no, but at least there&#8217;s a process where both sides will argue their points.)<\/p>\n\n\n\n<p>We do not particularly want to be a CNA but we hope that this move will make it harder to file more <a href=\"https:\/\/daniel.haxx.se\/blog\/2023\/08\/26\/cve-2020-19909-is-everything-that-is-wrong-with-cves\/\" data-type=\"post\" data-id=\"22951\">stupid curl CVEs<\/a> in the future.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The curl project has been accepted as a CVE Numbering Authority (CNA) for vulnerabilities in all products directly made or managed by the project. If I&#8217;m counting correctly, we are the 351st CNA. The official announcement from Mitre states: curl is now a CVE Numbering Authority (CNA) for all products made and managed by the &hellip; <a href=\"https:\/\/daniel.haxx.se\/blog\/2024\/01\/16\/curl-is-a-cna\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">curl is a CNA<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":5,"featured_media":19337,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[33,428],"class_list":["post-23736","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-curl","tag-curl-and-libcurl","tag-security"],"_links":{"self":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/23736","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/comments?post=23736"}],"version-history":[{"count":11,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/23736\/revisions"}],"predecessor-version":[{"id":24045,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/23736\/revisions\/24045"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/media\/19337"}],"wp:attachment":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/media?parent=23736"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/categories?post=23736"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/tags?post=23736"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}