curl / Docs / Vulnerability table / 8.6.0 vulnerabilities

Vulnerabilities in curl 8.6.0

curl version 8.6.0 was released on January 31 2024

It has the following 8 published security problems.

FlawFrom versionTo and including
HSTS subdomain overwrites parent cache entry7.74.08.10.1
OCSP stapling bypass with GnuTLS7.41.08.9.1
ASN.1 date parser overread7.32.08.9.0
freeing stack buffer in utf8asn1str8.6.08.8.0
TLS certificate check bypass with mbedTLS8.5.08.6.0
HTTP/2 push headers memory-leak7.44.08.6.0
QUIC certificate check bypass with wolfSSL8.6.08.6.0
Usage of disabled protocol7.85.08.6.0

Futher details

CVE data for 8.6.0 provided as JSON.

Changelog for curl 8.6.0

See vulnerability summary for the previous release: 8.5.0 or the subsequent release: 8.7.0