In two weeks we run the #curl distro meeting. You are invited!
https://daniel.haxx.se/blog/2026/01/28/curl-distro-meeting-2026/
#Tag
In two weeks we run the #curl distro meeting. You are invited!
https://daniel.haxx.se/blog/2026/01/28/curl-distro-meeting-2026/
My little #curl documentation fix is being shipped in version 8.19.0 🎉
chicken nuget
Insecure #curl packages hosted by Microsoft. They think it's fine.
chicken nuget
Insecure #curl packages hosted by Microsoft. They think it's fine.
@bagder I have a strong feeling you've already written about #Microsoft using outdated #curl version somewhere.
Am I hallucinating?
My little #curl documentation fix is being shipped in version 8.19.0 🎉
chicken nuget
Insecure #curl packages hosted by Microsoft. They think it's fine.
CVE-2026-3784 beat a new #curl record. This flaw existed in curl source code for 24.97 years before it was discovered.
Illustrated in the slightly hard-to-read graph below. The average age of a curl vulnerability when reported is eight years.
Welcome Vladimír Marek as #curl commit author 1452: https://github.com/curl/curl/pull/20885
#curl 8.19.0 release presentation by @bagder live now at https://www.twitch.tv/moderator/curlhacker
#curl 8.19.0 release presentation by @bagder live now at https://www.twitch.tv/moderator/curlhacker
@bagder #curl 8.19.0 Windows builds at https://curl.se/windows/ via https://github.com/curl/curl-for-win/commit/b64e9da1f0a39c4a4a43ec8c316c94d815db83ff
Welcome to #curl 8.19.0
https://daniel.haxx.se/blog/2026/03/11/curl-8-19-0/
8 changes, 4 vulnerabilities and 264 bugs fixed. Enjoy!
(The 4 new CVEs are explained in follow-up toots.)
@bagder #curl 8.19.0 Windows builds at https://curl.se/windows/ via https://github.com/curl/curl-for-win/commit/b64e9da1f0a39c4a4a43ec8c316c94d815db83ff
#curl 8.19.0, released today, has my reimplementation of rate limits for up- and downloads. They work the same for all network protocols and HTTP versions, and per URL, even on shared connections.
Meaning you can mix different limits (including unlimited) on the same HTTP/2 connection.
(This was not a goal as such, mainly a side effect of doing things properly. „Technical Credit“ I would call it. 😌)
#curl 8.19.0, released today, has my reimplementation of rate limits for up- and downloads. They work the same for all network protocols and HTTP versions, and per URL, even on shared connections.
Meaning you can mix different limits (including unlimited) on the same HTTP/2 connection.
(This was not a goal as such, mainly a side effect of doing things properly. „Technical Credit“ I would call it. 😌)
Welcome to #curl 8.19.0
https://daniel.haxx.se/blog/2026/03/11/curl-8-19-0/
8 changes, 4 vulnerabilities and 264 bugs fixed. Enjoy!
(The 4 new CVEs are explained in follow-up toots.)
Ahead of tomorrow's release of four new #curl CVEs I want you to know: we do our very best to secure curl every step of the way. Security is hard.
The end of the release cycle is really the peak. When a full cycle's worth of work and efforts are combined into a fresh tarball that is sent out into the cold harsh real world with the ideal outcome that everything just keeps on working exactly like before, ideally a little better.
The night before a release we believe this is the best we ever did. Every time we think this. Who knows what we will think tomorrow at this time.
Thanks for flying #curl. It's an adventure and honor to pilot this.
This is a Bonfire Federated social instance for those that enjoy gnarly adventures. Whether it's shredding mountains or slaying guitars, from action sports to art.