The curl project said in a blog post on 7 October 2026 that it will release curl 8.23.0 on 14 October. The release fixes 22 security flaws. One, CVE-2026-92392, is rated HIGH. The other 21 are less serious. The project moved the release a few weeks earlier than planned after getting a report about that one flaw. The latest stable version now, according to curl.se, is 8.22.0, released on 2 September 2026.
The project will publish details of CVE-2026-92392 on the morning of 14 October, European time, when 8.23.0 ships. Until then it is keeping them private. It will warn the distros@openwall mailing list and paying support customers ahead of time. The post does not say what the flaw is, how it is triggered, or which versions it affects. It does not say whether anyone has used it in attacks. It does not list the other 21 flaws. The project plans a longer write-up after 14 October.
curl.se says libcurl, the library form of curl, runs in over twenty billion installations, including routers, cars and phones. The project says it has rated only two flaws HIGH since 2021, the latest being CVE-2023-38545. Anyone who builds or runs software that uses curl will have a new release to review on 14 October.