curl / Docs / Vulnerability table / 8.13.0 vulnerabilities

Vulnerabilities in curl 8.13.0

curl version 8.13.0 was released on April 2 2025

It has the following 5 published security problems.

FlawFrom versionTo and including
predictable WebSocket mask8.11.08.15.0
Out of bounds read for cookie path7.31.08.15.0
WebSocket endless loop8.13.08.14.0
No QUIC certificate pinning with wolfSSL8.5.08.13.0
QUIC certificate check skip with wolfSSL8.8.08.13.0

Futher details

CVE data for 8.13.0 provided as JSON.

Changelog for curl 8.13.0

See vulnerability summary for the previous release: 8.12.1 or the subsequent release: 8.14.0