daniel.haxx.se
curl 8.22.0
Welcome to this new release. Get it as always from https://curl.se.
If you rather want a security-patched older release branch, stay tuned for the follow-up Rock-solid curl announcement within a few days.
## Release presentation
At 10:00 CEST (08:00 UTC) Daniel makes a live-streamed release presentation on Twich.
## Numbers
the 276th release
6 changes
70 days (total: 10,887)
302 bugfixes (total: 14,489)
525 commits (total: 39,608)
0 new public libcurl function (total: 100)
4 new curl_easy_setopt() option (total: 312)
4 new curl command line option (total: 278)
85 contributors, 55 new (total: 3,786)
43 authors, 29 new (total: 1,518)
9 security fixes (total: 215)
## Security
Associated with this release, we publish ten new CVEs. Nine of them are for curl and libcurl, and one is for wcurl.
* CVE-2026-13608: OpenLDAP SASL authentication bypass
* CVE-2026-18924: HTTP/2 server push UAF
* CVE-2026-19931: Negotiate ambient user conn reuse
* CVE-2026-80229: OpenSSL provider use-after-free
* CVE-2026-80230: OpenSSL pinning bypass
* CVE-2026-80231: native CA store conn reuse
* CVE-2026-80255: secure cookie attribute bypass with tab
* CVE-2026-82208: wolfSSL CA-cache hit overrides callback
* CVE-2026-82209: domain-scoped PSL domain cookie
The wcurl one:
CVE-2026-80256: wcurl backslash bypass
## Changes
* added support for Apple GSS Framework
* added API guards
* new RFC 9421 HTTP Message Signatures support (experimental)
* blocks NTLM fallback in SPNEGO negotiation
* dropped support for TLS-SRP
* added option to use Apple fast UDP
## Coming removals
* HTTP/2 Server Push
* local crypto implementations
* NTLM
* SMB
## Next
We plan the next curl release to happen at the end of October unless there are some bad regressions reported against 8.22.0.