Buy commercial curl support. We
help you work out your issues, debug your libcurl applications, use the API,
port to new platforms, add new features and more. With a team lead by the
curl founder Daniel himself.
[SECURITY ADVISORIES] curl 8.22.0
- Contemporary messages sorted: [ by date ] [ by thread ] [ by subject ] [ by author ] [ by messages with attachments ]
From: Daniel Stenberg via curl-users <curl-users_at_lists.haxx.se>
Date: Wed, 2 Sep 2026 08:22:10 +0200 (CEST)
Hello,
In association with curl 8.22.0 we announce these ten security advisories
addressing separate security vulneraiblities in curl, libcurl and wcurl.
We recommend you study the details in our write-ups. We try hard to explain
them in detail and include all sufficient details.
All new curl/libcurl are listed here: https://curl.se/docs/vuln-8.21.0.html
CVE-2026-13608: OpenLDAP SASL authentication bypass
CVE-2026-18924: HTTP/2 server push UAF
CVE-2026-19931: Negotiate ambient user conn reuse
CVE-2026-80229: OpenSSL provider use-after-free
CVE-2026-80230: OpenSSL pinning bypass
CVE-2026-80231: native CA store conn reuse
CVE-2026-80255: secure cookie attribute bypass with tab
CVE-2026-82208: wolfSSL CA-cache hit overrides callback
CVE-2026-82209: domain-scoped PSL domain cookie
CVE-2026-80256: wcurl backslash bypass
The wcurl problem is documented here:
https://curl.se/docs/CVE-2026-80256.html
Date: Wed, 2 Sep 2026 08:22:10 +0200 (CEST)
Hello,
In association with curl 8.22.0 we announce these ten security advisories
addressing separate security vulneraiblities in curl, libcurl and wcurl.
We recommend you study the details in our write-ups. We try hard to explain
them in detail and include all sufficient details.
All new curl/libcurl are listed here: https://curl.se/docs/vuln-8.21.0.html
CVE-2026-13608: OpenLDAP SASL authentication bypass
CVE-2026-18924: HTTP/2 server push UAF
CVE-2026-19931: Negotiate ambient user conn reuse
CVE-2026-80229: OpenSSL provider use-after-free
CVE-2026-80230: OpenSSL pinning bypass
CVE-2026-80231: native CA store conn reuse
CVE-2026-80255: secure cookie attribute bypass with tab
CVE-2026-82208: wolfSSL CA-cache hit overrides callback
CVE-2026-82209: domain-scoped PSL domain cookie
CVE-2026-80256: wcurl backslash bypass
The wcurl problem is documented here:
https://curl.se/docs/CVE-2026-80256.html
-- / daniel.haxx.se || https://rock-solid.curl.dev -- Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users Etiquette: https://curl.se/mail/etiquette.htmlReceived on 2026-09-02