curl / Docs / Vulnerability table / 8.21.0 vulnerabilities

Vulnerabilities in curl 8.21.0

curl version 8.21.0 was released on June 24 2026

It has the following 9 published security problems.

SFlawFirstLast
LCVE-2026-82209: domain-scoped PSL domain cookie7.46.08.21.0
LCVE-2026-82208: wolfSSL CA-cache hit overrides callback8.9.18.21.0
LCVE-2026-80255: secure cookie attribute bypass with tab8.13.08.21.0
LCVE-2026-80231: native CA store conn reuse7.71.08.21.0
LCVE-2026-80230: OpenSSL pinning bypass7.45.08.21.0
LCVE-2026-80229: OpenSSL provider use-after-free8.14.08.21.0
MCVE-2026-19931: Negotiate ambient user conn reuse7.64.18.21.0
LCVE-2026-18924: HTTP/2 server push UAF7.44.08.21.0
LCVE-2026-13608: OpenLDAP SASL authentication bypass7.82.08.21.0

Further details

CVE data for 8.21.0 provided as JSON.

Changelog for curl 8.21.0

See vulnerability summary for the previous release: 8.20.0 or the subsequent release: 8.22.0