Vulnerabilities in curl 8.15.0
curl version 8.15.0 was released on July 16 2025
It has the following 3 published security problems.
| Flaw | From version | To and including |
|---|---|---|
| missing SFTP host verification with wolfSSH | 7.69.0 | 8.16.0 |
| predictable WebSocket mask | 8.11.0 | 8.15.0 |
| Out of bounds read for cookie path | 7.31.0 | 8.15.0 |
Further details
CVE data for 8.15.0 provided as JSON.
See vulnerability summary for the previous release: 8.14.1 or the subsequent release: 8.16.0