Twenty-two pending curl vulnerabilities
Curl 8.23.0, due October 14, will fix 22 flaws including high-severity CVE-2026-92392.
The curl project will release curl 8.23.0 on October 14, 2026, ahead of schedule, to fix 22 security vulnerabilities. One issue, CVE-2026-92392, is rated HIGH, a rating the project has given only twice since 2021, most recently for heap overflow CVE-2023-38545. Technical details stay embargoed until the release; the distros list and paying support customers will be warned early. Maintainer Daniel Stenberg plans a later post on how the flaw is triggered and how it is fixed.
- curl 8.23.0 will ship on October 14, earlier than originally planned.
- The release fixes 22 vulnerabilities, including high-severity CVE-2026-92392.
- Flaw details stay private until release day; distros and paying customers get advance notice.
- curl has published only two HIGH CVEs since 2021, last being CVE-2023-38545.
Vulnerabilities mentionedAll →
- CVE-2023-385459.878%This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshakepublished · haxx libcurl
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|
Full article338 words · extracted from daniel.haxx.se · click to collapse
On October 14 2026 we will ship curl 8.23.0. The next iteration in the never-ending series of version bumps from the curl project.
We always think of the next release as the best version we ever did – and this time is no exception. Decades of collected experiences and meticulous polishing has lead us to this.
Earlier than planned
We decided to shorten the release cycle this time, so that we can release 8.23.0 a few weeks earlier than what we originally planned. We took this decision after we received one particular vulnerability report that highlighted a rather significant flaw.
We will ship a new version with this problem removed, together with twenty-one other albeit less serious security vulnerabilities addressed.
Severity HIGH
In the curl project we only assign one of the four different severity levels on all CVEs we report (LOW, MEDIUM, HIGH or CRITICAL), as we basically don’t believe in CVSS scoring. We have only published two CVEs with severity HIGH since 2021, the most recent one being CVE-2023-38545; that could lead to a heap buffer overflow.
Now we are about to release another one: CVE-2026-92392.
All info will be revealed next week
All details about CVE-2026-92392 will become public in the European morning of October 14, 2026 in synchronization of the release of curl 8.23.0 which of course will have this problem fixed.
We will ship updated Rock-solid curl versions in sync with this.
For the safety and security of curl users everywhere (and frankly, all the infrastructure that uses curl), no details of this flaw will be made public before this date.
We will alert the distros@openwall mailing list and paying curl support customers about this problem (and the associated fix) ahead of time.
I will follow-up with a separate blog post after October 14 to describe this flaw in detail. How it can be triggered, why it isn’t quite the end of the world and what we do in curl to fix this and similar classes of problems.
Post navigation
Text extracted automatically; images, tables and formatting may be missing. Original: https://daniel.haxx.se/blog/2026/10/07/twenty-two-pending-curl-vulnerabilities/