8.18.0 has been released. This release fixes 2 medium and 4 low level vulnerabilities:
- CVE-2025-13034: No QUIC certificate pinning with GnuTLS curl.se/docs/CVE-2025-13034.ht
- CVE-2025-14017: broken TLS options for threaded LDAPS curl.se/docs/CVE-2025-14017.ht
- CVE-2025-14524: bearer token leak on cross-protocol redirect curl.se/docs/CVE-2025-14524.ht
- CVE-2025-14819: OpenSSL partial chain store policy bypass curl.se/docs/CVE-2025-14819.ht
- CVE-2025-15079: libssh global knownhost override curl.se/docs/CVE-2025-15079.ht
- CVE-2025-15224: libssh key passphrase bypass without agent set curl.se/docs/CVE-2025-15224.ht

I discovered the last 2 vulnerabilities.

Download curl 8.18.0 from curl.se/download.html

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/harrysintonen/statuses/115852724607348302 on your instance and quote it. (Note that quoting is not supported in Mastodon.)