curl / Docs / Vulnerability table / 8.14.0 vulnerabilities

Vulnerabilities in curl 8.14.0

curl version 8.14.0 was released on May 28 2025

It has the following 10 published security problems.

FlawFrom versionTo and including
libssh key passphrase bypass without agent set7.58.08.17.0
libssh global known_hosts override7.58.08.17.0
OpenSSL partial chain store policy bypass7.87.08.17.0
bearer token leak on cross-protocol redirect7.33.08.17.0
broken TLS options for threaded LDAPS7.17.08.17.0
No QUIC certificate pinning with GnuTLS8.8.08.17.0
missing SFTP host verification with wolfSSH7.69.08.16.0
predictable WebSocket mask8.11.08.15.0
Out of bounds read for cookie path8.13.08.15.0
WebSocket endless loop8.13.08.14.0

Further details

CVE data for 8.14.0 provided as JSON.

Changelog for curl 8.14.0

See vulnerability summary for the previous release: 8.13.0 or the subsequent release: 8.14.1