Curl sets early 8.23.0 release for 22 flaws
Curl 8.23.0, due October 14, will fix 22 flaws including high-severity CVE-2026-92392; a separate post cites two arm64 miscompiles.
An October 6, 2026 report says curl maintainer Daniel Stenberg posted on Mastodon that two arm64-specific compiler miscompilations induce vulnerabilities in curl, without CVE identifiers, versions, patches, or any claim of exploitation. A following day's report says the project will ship curl 8.23.0 on October 14, 2026, ahead of schedule, to fix 22 security vulnerabilities, including high-severity CVE-2026-92392. The project said a HIGH rating has been used only twice since 2021, most recently for heap overflow CVE-2023-38545. Details remain private until release, while the distros list and paying support customers get advance notice, and Stenberg plans a later explanation of how the high-severity flaw is triggered and fixed. The sources do not state whether the arm64 miscompiles are part of the 22 flaws or related to CVE-2026-92392.
- An October 6, 2026 report says curl maintainer Daniel Stenberg posted that two arm64-specific compiler miscompilations induce vulnerabilities in curl.
- That report includes no CVE IDs, affected versions, patch details, or statement that the issues are being exploited.
- The curl project said it will release curl 8.23.0 on October 14, 2026, earlier than originally planned.
- The release is described as fixing 22 security vulnerabilities, including high-severity CVE-2026-92392.
- The project said it has assigned a HIGH rating only twice since 2021, most recently for heap overflow CVE-2023-38545.
- Technical details stay embargoed until release day; the distros list and paying support customers will be warned early.
- Stenberg plans a later post on how the high-severity flaw is triggered and how it is fixed.
- The reports do not say the two arm64 miscompiles are among the 22 flaws or linked to CVE-2026-92392.
Coverage timelineoldest first · each row is one article
- · 2d agoTwo arm64-specific miscompiles induce vulnerabilities in curl
Lobsters · security· 40
Curl's maintainer says two arm64-specific compiler miscompiles introduce vulnerabilities in curl.
- · 1d agoTwenty-two pending curl vulnerabilities
Lobsters · security· 72
Curl 8.23.0, due October 14, will fix 22 flaws including high-severity CVE-2026-92392.
Vulnerabilities in this storyAll →
- CVE-2023-385459.878%This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshakepublished · haxx libcurl
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure |
|---|