curl

150 posts

daniel:// stenberg://@bagder@mastodon.social
·

Including the pending CVEs, the top-20 most long-standing vulnerabilities ever found in curl are *all* older than 20 years. The oldest over 25 years.

daniel:// stenberg://@bagder@mastodon.social
·

Since March 1st 2026, we have received 143 vulnerability reports to the project. One new every 17 hours.

daniel:// stenberg://@bagder@mastodon.social
·

@joshbressers in the project we are about to announce the "curl summer of bliss". We will pause all work on vulnerabilities during the whole of July 2026. Details pending...

daniel:// stenberg://@bagder@mastodon.social
·

Out of the 16 pending CVEs:

13 are severity LOW
3 are severity MEDIUM
9 of them are libcurl only (not the tool)
3 are "C mistakes"
2 are younger than six months old
1 is older than 25 years

daniel:// stenberg://@bagder@mastodon.social
·

Since the latest release, we have received one confirmed vulnerability every 59th hour on average.

daniel:// stenberg://@bagder@mastodon.social
·

Number of Hackerone submissions to the first five months of 2026 compared to the same period of 2025. Counted weekly. The blue is 2026. The yellow is 2025.

daniel:// stenberg://@bagder@mastodon.social
·

It took a while but is officially at more than 13 test cases per 1000 lines of source code since today.