curl / Docs / Vulnerability table / 8.4.0 vulnerabilities

Vulnerabilities in curl 8.4.0

curl version 8.4.0 was released on October 11 2023. The following 4 security problems are known to exist in this version.

FlawFrom versionTo and including
HTTP/2 push headers memory-leak7.44.08.6.0
Usage of disabled protocol7.85.08.6.0
HSTS long file name clears contents7.84.08.4.0
cookie mixed case PSL bypass7.46.08.4.0

CVE data for 8.4.0 provided as JSON.

Changelog for curl 8.4.0

See vulnerability summary for the previous release: 8.3.0 or the subsequent release: 8.5.0