Discussion
Loading...

#curl

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
daniel:// stenberg://
daniel:// stenberg:// boosted
0x0
@0x0@hachyderm.io  ·  activity timestamp 2 days ago

The latest #curl update will now properly report long transfer times when sending data to Mars.

  • Copy link
  • Flag this post
  • Block
0x0
@0x0@hachyderm.io  ·  activity timestamp 2 days ago

The latest #curl update will now properly report long transfer times when sending data to Mars.

  • Copy link
  • Flag this post
  • Block
Stefan Eissing
@icing@chaos.social  ·  activity timestamp 3 days ago

Augment (which gave the #curl project free access) is changing pricing (again) in what seems to be a 10x increase.

Augment pricing changes from ‚messages‘ (number of answer which you control) to ‚credit‘ (which is effort controlled by Augment).

And this is probably still not enough to cover their real costs, not even speaking of profit.

Wherever you stand on the LLM debate, don‘t become dependant on those companies. Their business model sucks.

https://www.theregister.com/2025/10/15/augment_pricing_model/

Augment hikes price for AI code editor, users protest

: Second huge increase in six months sees some devs heading for the exit
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 3 days ago

Two years ago we dropped the years from all copyright mentions in the #curl project: https://daniel.haxx.se/blog/2023/01/08/copyright-without-years/

daniel.haxx.se

Copyright without years

Like so many other software projects the curl project has copyright mentions at the top of almost every file in the source code repository. Like Copyright (C) 1998 - 2022, Daniel Stenberg ... Over the years we have used a combination of scripts and manual edits to update the ending year in that copyright line … Continue reading Copyright without years →
2
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 3 days ago

In this latest #curl release, we are now three persons having our names on >10,000 lines of product code when doing git blame. @icing, @vsz and myself.

10 separate people have their names on 1000+ lines.

A graph showing how many people have curl source code lines attributed to them in git blame - over time.
A graph showing how many people have curl source code lines attributed to them in git blame - over time.
A graph showing how many people have curl source code lines attributed to them in git blame - over time.
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 5 days ago

#curl 8.18.0 with Daniel Stenberg

https://youtu.be/QVxFW6eqG_c

  • YouTube
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
1
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 5 days ago

#curl 8.18.0 has been released

https://daniel.haxx.se/blog/2026/01/07/curl-8-18-0/

daniel.haxx.se

curl 8.18.0

Download curl from curl.se! Release presentation On January 7 2026, at 10:00 CET (09:00 UTC), there is a live-streamed release presentation of curl 8.18.0 done on twitch. The YouTube recording will be made available afterwards. Numbers the 272nd release5 changes63 days (total: 10,155)391 bugfixes (total: 13,376)758 commits (total: 37,486)0 new public libcurl function (total: 100)0 … Continue reading curl 8.18.0 →
vsz
@vsz@mastodon.social (and 1 other) recently replied  ·  activity timestamp 5 days ago

@bagder #curl binaries for Windows are out at: https://curl.se/windows/ matching build log: https://ci.appveyor.com/project/curlorg/curl-for-win/builds/53332479

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg:// boosted
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 5 days ago

As always, I will live-stream a #curl release presentation at 10:00 CET (09:00 UTC) tomorrow on my twitch channel: https://www.twitch.tv/curlhacker

curlhacker - Twitch

curlhacker - Twitch

Twitch

curlhacker - Twitch
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg:// boosted
Harry Sintonen
@harrysintonen@infosec.exchange  ·  activity timestamp 5 days ago

#curl 8.18.0 has been released. This release fixes 1 medium and 5 low level vulnerabilities:
- CVE-2025-14017: broken TLS options for threaded LDAPS https://curl.se/docs/CVE-2025-14017.html
- CVE-2025-14524: bearer token leak on cross-protocol redirect https://curl.se/docs/CVE-2025-14524.html
- CVE-2025-14819: OpenSSL partial chain store policy bypass https://curl.se/docs/CVE-2025-14819.html
- CVE-2025-15079: libssh global knownhost override https://curl.se/docs/CVE-2025-15079.html
- CVE-2025-15224: libssh key passphrase bypass without agent set https://curl.se/docs/CVE-2025-15224.html

I discovered the last 2 vulnerabilities.

Download curl 8.18.0 from https://curl.se/download.html

#vulnerabilityresearch #vulnerability #cybersecurity #infosec

curl - Download

curl - libssh key passphrase bypass without agent set - CVE-2025-15224

curl - libssh global knownhost override - CVE-2025-15079

curl - OpenSSL partial chain store policy bypass - CVE-2025-14819

curl - bearer token leak on cross-protocol redirect - CVE-2025-14524

curl - broken TLS options for threaded LDAPS - CVE-2025-14017

  • Copy link
  • Flag this post
  • Block
Harry Sintonen
@harrysintonen@infosec.exchange  ·  activity timestamp 5 days ago

#curl 8.18.0 has been released. This release fixes 1 medium and 5 low level vulnerabilities:
- CVE-2025-14017: broken TLS options for threaded LDAPS https://curl.se/docs/CVE-2025-14017.html
- CVE-2025-14524: bearer token leak on cross-protocol redirect https://curl.se/docs/CVE-2025-14524.html
- CVE-2025-14819: OpenSSL partial chain store policy bypass https://curl.se/docs/CVE-2025-14819.html
- CVE-2025-15079: libssh global knownhost override https://curl.se/docs/CVE-2025-15079.html
- CVE-2025-15224: libssh key passphrase bypass without agent set https://curl.se/docs/CVE-2025-15224.html

I discovered the last 2 vulnerabilities.

Download curl 8.18.0 from https://curl.se/download.html

#vulnerabilityresearch #vulnerability #cybersecurity #infosec

curl - Download

curl - libssh key passphrase bypass without agent set - CVE-2025-15224

curl - libssh global knownhost override - CVE-2025-15079

curl - OpenSSL partial chain store policy bypass - CVE-2025-14819

curl - bearer token leak on cross-protocol redirect - CVE-2025-14524

curl - broken TLS options for threaded LDAPS - CVE-2025-14017

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 5 days ago

#curl 8.18.0 has been released

https://daniel.haxx.se/blog/2026/01/07/curl-8-18-0/

daniel.haxx.se

curl 8.18.0

Download curl from curl.se! Release presentation On January 7 2026, at 10:00 CET (09:00 UTC), there is a live-streamed release presentation of curl 8.18.0 done on twitch. The YouTube recording will be made available afterwards. Numbers the 272nd release5 changes63 days (total: 10,155)391 bugfixes (total: 13,376)758 commits (total: 37,486)0 new public libcurl function (total: 100)0 … Continue reading curl 8.18.0 →
2
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 5 days ago

6,000 #curl stickers: https://daniel.haxx.se/blog/2026/01/06/6000-curl-stickers/

daniel.haxx.se

6,000 curl stickers

I am heading to FOSDEM again at the end of January. I go there every year and I have learned that there is a really sticker-happy audience there. The last few times I have been there, I have given away several thousands of curl stickers. As I realized I did not actually have a few … Continue reading 6,000 curl stickers →
1
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 5 days ago

As always, I will live-stream a #curl release presentation at 10:00 CET (09:00 UTC) tomorrow on my twitch channel: https://www.twitch.tv/curlhacker

curlhacker - Twitch

curlhacker - Twitch

Twitch

curlhacker - Twitch
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 5 days ago

The list of top #curl sponsors remains the exact same release after release...

curl top sponsors Jan 2026: Haxx, wolfSSL, Fastly, TeamViewer, GitHub, kirei, IBB, Elastic
curl top sponsors Jan 2026: Haxx, wolfSSL, Fastly, TeamViewer, GitHub, kirei, IBB, Elastic
curl top sponsors Jan 2026: Haxx, wolfSSL, Fastly, TeamViewer, GitHub, kirei, IBB, Elastic
6
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 6 days ago

I spend a ridiculous amount of my time on #curl security these days. Because I think that's my responsibility.

something something open source sustainability

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 6 days ago

buckle up and prepare for an unload of *six* CVEs against #curl getting published tomorrow, severity low and medium

1
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 6 days ago

The year's 6th day just started and we just clocked in our 8th hackerone report on #curl for the year.

This doesn't work.

4
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 6 days ago

less than 24 hours to the next #curl release...

1
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 6 days ago

6,000 #curl stickers. 3 Kg.

Get yours at #FOSDEM

6,000 curl stickers in six different variants
6,000 curl stickers in six different variants
6,000 curl stickers in six different variants
7
  • Copy link
  • Flag this post
  • Block
Log in

Gnar 🔥 social

This is a Bonfire Federated social instance for those that enjoy gnarly adventures. Whether it's shredding mountains or slaying guitars, from action sports to art.

Gnar 🔥 social: About · Code of conduct · Privacy · Users · Instances
Gnar;🔥 social · 1.0.0-rc.3.6 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login