{"id":30635,"date":"2026-10-07T09:12:11","date_gmt":"2026-10-07T07:12:11","guid":{"rendered":"https:\/\/daniel.haxx.se\/blog\/?p=30635"},"modified":"2026-10-07T09:12:11","modified_gmt":"2026-10-07T07:12:11","slug":"twenty-two-pending-curl-vulnerabilities","status":"publish","type":"post","link":"https:\/\/daniel.haxx.se\/blog\/2026\/10\/07\/twenty-two-pending-curl-vulnerabilities\/","title":{"rendered":"Twenty-two pending curl vulnerabilities"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On October 14 2026 we will ship curl 8.23.0. The next iteration in the never-ending series of  version bumps from the <a href=\"https:\/\/curl.se\/\">curl project<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We always think of the next release as the best version we ever did &#8211; and this time is no exception. Decades of collected experiences and meticulous polishing has lead us to this.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Earlier than planned<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We decided to shorten the release cycle this time, so that we can release 8.23.0 a few weeks earlier than what we originally planned. We took this decision after we received one particular vulnerability report that highlighted a rather significant flaw.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We will ship a new version with this problem removed, together with twenty-one other albeit less serious security vulnerabilities addressed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Severity HIGH<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the curl project we only assign one of the four different  severity levels on all CVEs we report (LOW, MEDIUM, HIGH or CRITICAL), as we basically <a href=\"https:\/\/daniel.haxx.se\/blog\/2025\/01\/23\/cvss-is-dead-to-us\/\" data-type=\"post\" data-id=\"26318\">don&#8217;t believe in CVSS scoring<\/a>.  We have only published two CVEs with severity HIGH since 2021, the most recent one being <a href=\"https:\/\/curl.se\/docs\/CVE-2023-38545.html\">CVE-2023-38545<\/a>; that could lead to a heap buffer overflow.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now we are about to release another one: CVE-2026-92392.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">All info will be revealed next week<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">All details about CVE-2026-92392 will become public in the European morning of October 14, 2026 in synchronization of the release of curl 8.23.0 which of course will have this problem fixed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We will ship updated <a href=\"https:\/\/rock-solid.curl.dev\/\">Rock-solid curl<\/a> versions in sync with this.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For the safety and security of curl users everywhere (and frankly, all the infrastructure that uses curl), no details of this flaw will be made public before this date.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We will alert the distros@openwall mailing list and paying curl support customers about this problem (and the associated fix) ahead of time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I will follow-up with a separate blog post after October 14 to describe this flaw in detail. How it can be triggered, why it isn&#8217;t quite the end of the world and what we do in curl to fix this and similar classes of problems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On October 14 2026 we will ship curl 8.23.0. The next iteration in the never-ending series of version bumps from the curl project. We always think of the next release as the best version we ever did &#8211; and this time is no exception. Decades of collected experiences and meticulous polishing has lead us to &hellip; <a href=\"https:\/\/daniel.haxx.se\/blog\/2026\/10\/07\/twenty-two-pending-curl-vulnerabilities\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Twenty-two pending curl vulnerabilities<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":5,"featured_media":12595,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[33,428],"class_list":["post-30635","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-curl","tag-curl-and-libcurl","tag-security"],"_links":{"self":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/30635","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/comments?post=30635"}],"version-history":[{"count":5,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/30635\/revisions"}],"predecessor-version":[{"id":30664,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/30635\/revisions\/30664"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/media\/12595"}],"wp:attachment":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/media?parent=30635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/categories?post=30635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/tags?post=30635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}