curl / Mailing Lists / curl-users / Single Mail
Buy commercial curl support. We help you work out your issues, debug your libcurl applications, use the API, port to new platforms, add new features and more. With a team lead by the curl founder Daniel himself.

[SECURITY ADVISORIES] curl 8.22.0

From: Daniel Stenberg via curl-users <curl-users_at_lists.haxx.se>
Date: Wed, 2 Sep 2026 08:22:10 +0200 (CEST)

Hello,

In association with curl 8.22.0 we announce these ten security advisories
addressing separate security vulneraiblities in curl, libcurl and wcurl.

We recommend you study the details in our write-ups. We try hard to explain
them in detail and include all sufficient details.

All new curl/libcurl are listed here: https://curl.se/docs/vuln-8.21.0.html

CVE-2026-13608: OpenLDAP SASL authentication bypass

CVE-2026-18924: HTTP/2 server push UAF

CVE-2026-19931: Negotiate ambient user conn reuse

CVE-2026-80229: OpenSSL provider use-after-free

CVE-2026-80230: OpenSSL pinning bypass

CVE-2026-80231: native CA store conn reuse

CVE-2026-80255: secure cookie attribute bypass with tab

CVE-2026-82208: wolfSSL CA-cache hit overrides callback

CVE-2026-82209: domain-scoped PSL domain cookie

CVE-2026-80256: wcurl backslash bypass

The wcurl problem is documented here:

   https://curl.se/docs/CVE-2026-80256.html

-- 
  / daniel.haxx.se || https://rock-solid.curl.dev
-- 
Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users
Etiquette:   https://curl.se/mail/etiquette.html
Received on 2026-09-02