curl / Docs / Vulnerability table / 8.19.0 vulnerabilities

Vulnerabilities in curl 8.19.0

curl version 8.19.0 was released on March 11 2026

It has the following 26 published security problems.

FlawFrom versionTo and including
proto-default skips SSH verification7.81.08.20.0
cross-origin Digest auth state leak7.10.68.20.0
WS Auto-PONG memory exhaustion8.16.08.20.0
Native CA trust persist8.17.08.20.0
QUIC zero-length UDP datagrams busy-loop8.18.08.20.0
HTTP/2 stream-dependency tree UAF7.88.08.20.0
SSH improper host validation7.69.08.20.0
sending old referer8.18.08.20.0
exposing HTTP/3 early data8.11.08.20.0
UAF after pause in socket callback8.13.08.20.0
stale proxy password leak8.8.08.20.0
incomplete mTLS config matching in conn reuse7.78.20.0
env-set cross-proxy Digest auth state leak7.12.08.20.0
password leak with netrc and user in URL8.11.18.20.0
SASL double-free8.15.08.20.0
trailing dot domain super cookie7.46.08.20.0
wrong reuse for different services7.43.08.20.0
wrong STARTTLS connection reuse7.30.08.20.0
cross-proxy Digest auth state leak7.12.08.19.0
OCSP stapling bypass with Apple SecTrust8.17.08.19.0
netrc credential leak with reused proxy connection7.14.08.19.0
stale custom cookie host causes cookie leak7.71.08.19.0
proxy credentials leak over redirect-to proxy7.14.18.19.0
wrong reuse of SMB connection7.40.08.19.0
wrong reuse of HTTP Negotiate connection7.10.68.19.0
connection reuse ignores TLS requirement7.20.08.19.0

Further details

CVE data for 8.19.0 provided as JSON.

Changelog for curl 8.19.0

See vulnerability summary for the previous release: 8.18.0 or the subsequent release: 8.20.0