Sign in

daniel:// stenberg://

@bagder.mastodon.social.ap.brid.gy
3.3K followers 0 following 3.7K posts

I write curl. I don't know anything. 🌉 bridged from ⁂ mastodon.social/@bagder, follow @ap.brid.gy to interact

PostsRepliesMedia
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 39m
I still get no comments or questions about CRA in regards to #curl
000
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 8h
and whatdoyouknow: we're now at 24 pending CVEs
180
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 9h
Welcome İlyas Serdar Dursun as #curl commit author 1544: github.com/curl/curl/pull/23319
github.com
connect: keep IP info and connect time when connect fails by iserdardursun · Pull Request #23319 · curl/curl
When the connect timeout triggers during the TLS handshake, the transfer reports no remote_ip, local_ip or time_connect even though TCP was connected. The same happens when the TLS handshake fails....
020
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 10h
"Launching an opt-in vulnerability-finding service for open-source software" / Anthropic www.anthropic.com/research/launchin…
anthropic.com
An opt-in vulnerability-finding service for open-source software
We’re launching OSS Scanner, an opt-in vulnerability scanner for the open-source ecosystem informed by our experience using Claude to find vulnerabilities during Project Glasswing. Projects that join will receive thorough, periodic security scans by our strongest models at no cost.
3317
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 18h
been so preoccupied by vuln reports I totally missed writing a nonsense blog post about #curl surpassing 40,000 git commits
190
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 19h
and in case you thought having twenty-two pending CVEs in the pipeline for publishing would in any way cause the inflow of reports to slow down, think again... 😰
170
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 08/10/2026
We've had 154 commit authors in #curl so far in 2026. Exactly as many as we had during the entire year 2025...
030
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 08/10/2026
Next week we'll publish a 54 page "audit report" detailing every #curl vulnerability finding the good people at Aisle found in curl (so far) - all 35 of them.
082
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 08/10/2026
"The people holding up the internet" A good-looking but somewhat depressing exposé about the people holding up current digital infrastructure as a hobby. sheets.works/data-viz/holding-up-th…
sheets.works
The people holding up the internet
Four billion phones ask one text file what time it is. One lecturer keeps it in his spare time. We counted the rest.
249162
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 07/10/2026
"Here you can find a full list of all New gTLD Program: 2026 Round applications" Yeps, exactly as crazy as you can imagine. newgtldprogram-aps.icann.org/applic…
newgtldprogram-aps.icann.org
Applications
New gTLD Program: 2026 Round public application information, including application status.
223
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 07/10/2026
I'm a little miffed someone read something else into a previous post of mine so let me clear that up: gcc is an outstanding project and compiler set. We owe so much to them.
063
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 07/10/2026
Twenty-two pending #curl vulnerabilities daniel.haxx.se/blog/2026/10/07/twen…
daniel.haxx.se
Twenty-two pending curl vulnerabilities
On October 14 2026 we will ship curl 8.23.0. The next iteration in the never-ending series of version bumps from the curl project. We always think of the next release as the best version we ever did – and this time is no exception. Decades of collected experiences and meticulous polishing has lead us to this. ## Earlier than planned We decided to shorten the release cycle this time, so that we can release 8.23.0 a few weeks earlier than what we originally planned. We took this decision after we received one particular vulnerability report that highlighted a rather significant flaw. We will ship a new version with this problem removed, together with twenty-one other albeit less serious security vulnerabilities addressed. ## Severity HIGH In the curl project we only assign one of the four different severity levels on all CVEs we report (LOW, MEDIUM, HIGH or CRITICAL), as we basically don’t believe in CVSS scoring. We have only published two CVEs with severity HIGH since 2021, the most recent one being CVE-2023-38545; that could lead to a heap buffer overflow. Now we are about to release another one: CVE-2026-92392. ## All info will be revealed next week All details about CVE-2026-92392 will become public in the European morning of October 14, 2026 in synchronization of the release of curl 8.23.0 which of course will have this problem fixed. We will ship updated Rock-solid curl versions in sync with this. For the safety and security of curl users everywhere (and frankly, all the infrastructure that uses curl), no details of this flaw will be made public before this date. We will alert the distros@openwall mailing list and paying curl support customers about this problem (and the associated fix) ahead of time. I will follow-up with a separate blog post after October 14 to describe this flaw in detail. How it can be triggered, why it isn’t quite the end of the world and what we do in curl to fix this and similar classes of problems.
0111
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 07/10/2026
Buckle up. One of the pending #curl CVEs that we publish next week is graded severity HIGH. Considered the worst flaw found in curl in several years. Yes, found with AI.
43835
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 07/10/2026
7 days to the next #curl release. 22 pending CVE announcements. 230+ bugfixes. 37 authors. SMB support is dropped.
142
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 07/10/2026
The third and final release candidate of the coming #curl release is now available at curl.se/rc Do not use release candidates in production. They are work in progress. Use them for testing and verification only. Use actual releases in production.
curl.se
curl release candidates
020
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 06/10/2026
here's my slideset from my presentation today: daniel.haxx.se/media/Netnod%20Tech%…
041
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 06/10/2026
Google closing their VDP OSS program made half a dozen journalists email me for comments. I've told them: in the open source world we don't anymore have the slop problem Google seem to address now, half a year after we've seen it mostly go away by itself. These days, we have a high volume high […]
mastodon.social
Original post on mastodon.social
072
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 06/10/2026
This week in #curl we get to experience not one, but two compiler bugs. All research by @vsz. Two arm64-specific compiler optimization bugs, in gcc-15/16 and Rust respectively: github.com/curl/curl/issues/23237
github.com
OpenSSL 3/4 and quiche H3 valgrind issues on arm64 · Issue #23237 · curl/curl
OpenSSL 3, 4 on arm64 H3 valgrind fails: FAIL 2500: 'HTTP/3 GET:' HTTP, HTTP GET, HTTP/3, --resolve FAIL 2501: 'HTTP/3 POST' HTTP, HTTP POST, HTTP/3, HTTPS FAIL 2502: 'HTTP GET multiple over HTTP/3...
070
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 06/10/2026
Today I will speak at the Netnod Tech meeting 2026 in Stockholm: www.netnod.se/netnod-tech-meeting-2…
010
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 06/10/2026
I'll write up a proposal. Any other topic you think I should suggest?
mastodon.social
013
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 05/10/2026
Meat proxy as a service. hackerone.com/reports/4064040
hackerone.com
curl disclosed on HackerOne: Use-after-free read of the freed...
(CWE-416 → CWE-908/CWE-200) ## Aset yang terdampak (Affected Asset) - **Component:** libcurl — `lib/setopt.c`, `CURLOPT_REFERER` handler (`curl_easy_setopt` API) - **Related code paths:**...
4126
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 05/10/2026
"Google freezes open-source bug bounty program amid flood of invalid AI slop submissions" […]
mastodon.social
Original post on mastodon.social
3928
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 05/10/2026
No, AI is not causing a PR or commit author explosion in #curl (so far)
commit authors per year in the curl project, showing 2026 pretty much on par with recent yearscommits per year in the curl project, showing 2026 slightly behind last year
092
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 04/10/2026
I'll be at FOSSCOMM 2026 in Athens, Greece, at the end of this month and blab. 2026.fosscomm.gr
2026.fosscomm.gr
FOSSCOMM 2026
19th Panhellenic FOSS Communities Meeting
020
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 04/10/2026
Sometimes it feels like I could spend all my days just participating in interviews for various studies that somehow involve Open Source.
031
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 01/10/2026
There's a new browser in town using #libcurl for transfers: nordstjernen.org
nordstjernen.org
Nordstjernen Web Browser
A web browser written from scratch in C.
167
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 25/09/2026
my week: lists.haxx.se/pipermail/daniel/2026… 25 years, security, performance, Rock-solid, Development, rc2, stickers
You wouldn't rewrite curl
191
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 25/09/2026
"the kernel.org CNA has CVE-2026-100000 reserved" 🍾 / @gregkh
1111
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 25/09/2026
If you're heading to the #OpenSSL conf in Prague Oct 13-15 make sure you chase down @jimfuller and unload him of a few #curl stickers. He's going to be our official distributor there. You can have your fix from him. For free. You know you need one. Or two.
the curl logo, looking like a die cut sticker
130
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 25/09/2026
Today we celebrate #curl 25 years on Apple computers: daniel.haxx.se/blog/2026/09/25/25-y…
daniel.haxx.se
25 years on Apple computers
Exactly on this day, September 25 2001, Apple shipped version 10.1 of their OS X operating system. The one they later would rename to macOS. Exactly twenty-five years ago today. Within all their fancy release presentations and videos there are barely no mentions of curl. In their technical notes page, there is just this short single line with not a lot of explanations: Ever since then, curl has been an established component, present in every version and every install of macOS done through the decades. When Apple later created iOS, iPadOS, WatchOS etc they also adopted libcurl into their operating systems. Never to provide the API to users, but to empower their own applications and services. (But I have no specific date logged anywhere when that started.) The first curl version Apple shipped in macOS was curl 7.7.2 which was released in April that same year. Apple has never used a super recent curl version but they have updated it reasonably well I would say. Sometimes less good. We are proud to have been a part of the Internet evolution all this time. We are happy that Apple, even if merely implied, has validated us and our way of doing things. We have never worked with Apple, never received sponsorship by Apple, not had them as customers and except a few rare and mostly failed attempts there have never been any communication between us. We ship a freely available Open Source product that they use and bundle in their products. (It is their choice and right.)
3113
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 25/09/2026
Organisation curl Job title internet janitor Attending Social: No Filling in the registration form for a conference talk I'll do in a few weeks.
251
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 25/09/2026
#curl 8.23.0-rc2 is here. The second release candidate: curl.se/rc Do not use release candidates in production. They are work in progress. Use them for testing and verification only. Use actual releases in production.
curl.se
curl release candidates
020
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 25/09/2026
Rock-solid #curl with Daniel Stenberg youtu.be/w7-St22V1sA
022
Reposted by daniel:// stenberg://
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 21/09/2026
I'll do a free webinar on Thursday about our long term support #curl branches we call rock-solid curl: us02web.zoom.us/webinar/register/80…
043
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 23/09/2026
When we announce over 20 new #curl CVEs on October 14, you will learn that every single one of them were found by clever humans using harnesses powered by AI models. Every. Single. One. The holy trinity of modern vulnerability research.
2126
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 23/09/2026
Another security person said this about #curl in an email to me the other day: "Maybe we're really headed towards curl being the most informally verified library in existence (although it seems to me it likely already is)."
152
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 23/09/2026
Dan Lorenc at Chainguard posted this statement about #curl on LinkedIn...
We put curl 8.22.0 through an eight-and-a-half-hour automated tree search, about 4,100 tool calls and roughly 190 million tokens of model work (the vast majority cache reads), aimed only at High and Critical outcomes: memory safety on an ASan build across the HTTP/1, HTTP/2, HTTP/3, WebSocket, FTP, IMAP, POP3, SMTP, SMB, LDAP, cookie, and NTLM/Digest/Negotiate parsers under tens of thousands of hostile server responses, plus integrity hunts for TLS verification bypass under an on-path attacker,
STARTTLS and 1implicit-TLS downgrade, cross-handle response confusion, CONNECT tunnel handling, credential leakage through redirects, file writes outside the output directory, and Alt-Svc and HSTS guarantees. Thirty-one lines of attack closed clean with no sanitizer report and no verification
bypass; all that surfaced were three Medium-class edges, one of which the curl team had already fixed on master days before we looked. That outcome is a credit to the project: years of continuous fuzzing, the maintainers' own audits, and a codebase where every server-controlled length is bounded
before use left a persistent automated adversary with nowhere to go. Congratulations to the curl team, and thanks for making our negative result so thoroughly earned.

One note on the token figure: the run log records usage for only about 400 of the turns (18.6 million tokens, 46,500 per turn on average), so the 190 million is that average scaled to the 4,103 tool-call turns.
21614
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 22/09/2026
we received a list with ~160 #curl bugs (explicitly *not* vulns) from Aisle that now sits in a private repo for us to work through over time. Things they fell over while scanning for issues. Nothing major, but smaller things we might want to polish.
030
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 21/09/2026
I'll do a free webinar on Thursday about our long term support #curl branches we call rock-solid curl: us02web.zoom.us/webinar/register/80…
043
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 21/09/2026
Welcome Filippo Tedeschi as #curl commit author 1536: github.com/curl/curl/pull/23020
github.com
getinfo: make sure CURLINFO_REDIRECT_URL does not contain creds by filtede98 · Pull Request #23020 · curl/curl
Summary Follow-up to commit 7a6bd02 (#23016): make sure data->info.wouldredirect (exposed via CURLINFO_REDIRECT_URL and %{redirect_url}) does not contain credentials inherited from the original ...
010
Reposted by daniel:// stenberg://
Julia Evans @b0rk.social.jvns.ca.ap.brid.gy · 21/09/2026
Are you interested in learning how to use Git for the first time? (or almost the first time) we're looking for Git beginners to give us feedback on a Git tutorial! The tutorial will be open source when it's released, so you'll be helping many future beginners! Sign up here […]
social.jvns.ca
Original post on social.jvns.ca
6673
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 21/09/2026
At 22 confirmed #curl vulnerabilities queued up to announce on October 14...
040
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 21/09/2026
because obviously on Windows "CON[superscript 1]" is also a reserved file name... *sigh* And yeah, you can write that either with ISO8859-1 *or* UTF-8 ... You couldn't even make these things up if you tried.
6109
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 21/09/2026
Welcome to minnnjuuu as #curl commit author 1535: github.com/curl/curl/pull/23008
github.com
examples: clean up crawler link parsing resources by minnnjuuu · Pull Request #23008 · curl/curl
What is the purpose of the change? follow_links() owns the libxml document returned by htmlReadMemory() and each xmlChar URL returned by xmlNodeListGetString() or xmlBuildURI(). The document was no...
000
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 20/09/2026
Welcome Jorge Rocamora as #curl commit author 1534: github.com/curl/curl/pull/23005
github.com
vssh: do not busy-loop in blocking state machine without a timeout by aeroyorch · Pull Request #23005 · curl/curl
Avoid busy loop in SSH state machines (both libssh and libssh2) when Curl_timeleft_ms() returns 0 (i.e. no timeout).
001
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 18/09/2026
my week: lists.haxx.se/pipermail/daniel/2026… security, performance, events
A wooden "robot" with a curl sticker at its feet.
0102
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 18/09/2026
#curl 8.23.0 release candidate one is up: curl.se/rc Please take it for a spin and double-check that it works just as smooth as you would expect. Do not use release candidates in production. They are work in progress. Use them for testing and verification only. Use actual releases in […]
mastodon.social
Original post on mastodon.social
010
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 18/09/2026
I had a look at the “project number of CVEs” that we estimated back at #curl up in late May. We then said it could end up at 55 by the end of the year. As we now already have published 45 and there are (at least) 20 coming, we have certainly exceeded those projections. The question is now rather […]
mastodon.social
Original post on mastodon.social
070
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 18/09/2026
Last year I blogged about the vulnerability reporting process in #curl. It remains the same, just with about 3-4x the volume... daniel.haxx.se/blog/2025/09/18/from…
daniel.haxx.se
From suspicion to published curl CVE
Every curl security report starts out with someone submitting an issue to us on https://hackerone.com/curl. The reporter tells us what they suspect and what they think the problem is. This report is kept private, visible only to the curl security team and the reporter while we work on it. In recent months we have gotten 3-4 security reports per week. The program has run for over six years now, with almost 600 reports accumulated. On average, someone in the team makes a first response to that report already within the first hour. ## Assess The curl security team right now consists of seven long time and experienced curl maintainers. We immediately start to analyze and assess the received issue and its claims. Most reports are not identifying actual security problems and are instead quickly dismissed and closed. Some of them identify plain bugs that are not security issues and then we move the discussion over to the public bug tracker instead. This part can take anything from hours up to multiple days and usually involves several curl security team members. If we think the issue might have merit, we ask follow-up questions, test reproducible code and discuss with the reporter. ## Valid A small fraction of the incoming reports is actually considered valid security vulnerabilities. We work together with the reporter to reach a good understanding of what exactly is required for the bug to trigger and what the flaw can lead to. Together we set a _severity_ for the problem (low, medium, high, critical) and we work out a first patch – which also helps to make sure we understand the issue. Unless the problem is deemed serious we tend to sync the publication of the new vulnerability with the pending next release. Our normal release cycle is eight weeks so we are never farther than 56 days away from the next release. ## Fix For security issues we deem to be severity low or medium we create a pull request for the problem in the public repository – but we don’t mention the security angle of the problem in the public communication of it. This way, we also make sure that the fix gets added test exposure and time to get polished before the pending next release. Over the last five or so years, only two in about eighty confirmed security vulnerabilities have been rated a higher severity than medium. Fixes for vulnerabilities we consider to be severity high or critical are instead merged into the git repository when there is approximately 48 hours left to the pending release – to limit the exposure time before it is announced properly. We need to merge it into the public before the release because our entire test infrastructure and verification system is based on public source code. ## Advisory Next, we write up a detailed security advisory that explains the problem and exactly what the mistake is and how it can lead to something bad – including all the relevant details we can think of. This includes version ranges for affected curl versions and the exact git commits that introduced the problem as well as which commit that fixed the issue – plus credits to the reporter and to the patch author etc. We have the ambition to provide the best security advisories you can find in the industry. (We also provide them in JSON format etc on the site for the rare few users who care about that.) We of course want the original reporter involved as well so that we make sure that we get all the angles of the problem covered accurately. ## CVE As we are a CNA (CVE Numbering Authority), we reserve and manage CVE Ids for our own issues ourselves. ## Pre-notify About a week before the pending release when we also will publish the CVE, we inform the distros@openwall mailing list about the issue, including the fix, and when it is going to be released. It gives Open Source operating systems a little time to prepare their releases and adjust for the CVE we will publish. ## Publish On the release day we publish the CVE details and we ship the release. We then also close the HackerOne report and disclose it to the world. We disclose all HackerOne reports once closed for maximum transparency and openness. We also inform all the curl mailing lists and the oss-security mailing list about the new CVE. Sometimes we of course publish more than one CVE for the same release. ## Bounty Once the HackerOne report is closed and disclosed to the world, the vulnerability reporter can claim a bug bounty from the Internet Bug Bounty which pays the researcher a certain amount of money based on the severity level of the curl vulnerability. (The original text I used for this blog post was previously provided to the interview I made for Help Net Security. Tweaked and slightly extended here.) ## The team The heroes in the curl security team who usually work on all this in silence and without much ado, are currently (in no particular order): * Max Dymond * Dan Fandrich * Daniel Gustafsson * James Fuller * Viktor Szakats * Stefan Eissing * Daniel Stenberg
051
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 17/09/2026
Between all the vulnerability report work, I made curl's date parser twice as fast as before... curl.se/perf/#dateparser
date parsing speed dropping from ~59ns down to 27ns per invoke (on a test with 180 different date strings)
072