curl / Docs / Vulnerability table / 8.19.0 vulnerabilities

Vulnerabilities in curl 8.19.0

curl version 8.19.0 was released on March 11 2026

It has the following 8 published security problems.

FlawFrom versionTo and including
cross-proxy Digest auth state leak7.12.08.19.0
OCSP stapling bypass with Apple SecTrust8.17.08.19.0
netrc credential leak with reused proxy connection7.14.08.19.0
stale custom cookie host causes cookie leak7.71.08.19.0
proxy credentials leak over redirect-to proxy7.14.18.19.0
wrong reuse of SMB connection7.40.08.19.0
wrong reuse of HTTP Negotiate connection7.10.68.19.0
connection reuse ignores TLS requirement7.20.08.19.0

Further details

CVE data for 8.19.0 provided as JSON.

Changelog for curl 8.19.0

See vulnerability summary for the previous release: 8.18.0 or the subsequent release: 8.20.0