Skip to content
Brief Security & Trust ·

curl to fix 22 flaws on 14 October, including one rated HIGH

The curl project is keeping details of its most serious flaw private until the 8.23.0 release.

In brief
  • curl 8.23.0 arrives on 14 October and fixes 22 security flaws. One, CVE-2026-92392, is rated HIGH.
  • The project has not said what the flaw is or which versions it affects.

The curl project said in a blog post on 7 October 2026 that it will release curl 8.23.0 on 14 October. The release fixes 22 security flaws. One, CVE-2026-92392, is rated HIGH. The other 21 are less serious. The project moved the release a few weeks earlier than planned after getting a report about that one flaw. The latest stable version now, according to curl.se, is 8.22.0, released on 2 September 2026.

The project will publish details of CVE-2026-92392 on the morning of 14 October, European time, when 8.23.0 ships. Until then it is keeping them private. It will warn the distros@openwall mailing list and paying support customers ahead of time. The post does not say what the flaw is, how it is triggered, or which versions it affects. It does not say whether anyone has used it in attacks. It does not list the other 21 flaws. The project plans a longer write-up after 14 October.

curl.se says libcurl, the library form of curl, runs in over twenty billion installations, including routers, cars and phones. The project says it has rated only two flaws HIGH since 2021, the latest being CVE-2023-38545. Anyone who builds or runs software that uses curl will have a new release to review on 14 October.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: curl project.