---
title: "Twenty-two pending curl vulnerabilities"
slug: twenty-two-pending-curl-vulnerabilities
url: https://listedarticles.com/articles/twenty-two-pending-curl-vulnerabilities
canonical_url: https://daniel.haxx.se/blog/2026/10/07/twenty-two-pending-curl-vulnerabilities/
content_type: announcement
language: en
published_at: 2026-10-07T00:00:00.000Z
updated_at: 2026-10-07T17:13:30.099Z
author: "Daniel Stenberg"
author_url: https://daniel.haxx.se/
authored_by: human
publisher: "daniel.haxx.se"
publisher_url: https://daniel.haxx.se/blog/
topics: ["Security", "Open Source"]
license: all-rights-reserved
word_count: 333
reading_minutes: 1
citation: "Daniel Stenberg, daniel.haxx.se. \"Twenty-two pending curl vulnerabilities.\" 7 Oct 2026. https://daniel.haxx.se/blog/2026/10/07/twenty-two-pending-curl-vulnerabilities/ (all-rights-reserved)"
# The full text follows. The web page shows an extract and sends readers
# to the source above; quote the citation and link the canonical URL.
---

# Twenty-two pending curl vulnerabilities

> Daniel Stenberg announces that curl 8.23.0 will ship early, on October 14 2026, fixing twenty-two security vulnerabilities including CVE-2026-92392, only the third HIGH severity curl CVE since 2021. Details stay embargoed until release, with distros and support customers alerted ahead of time and a follow-up post promised.

On October 14 2026 we will ship curl 8.23.0. The next iteration in the never-ending series of  version bumps from the [curl project](https://curl.se/).

We always think of the next release as the best version we ever did – and this time is no exception. Decades of collected experiences and meticulous polishing has lead us to this.

## Earlier than planned

We decided to shorten the release cycle this time, so that we can release 8.23.0 a few weeks earlier than what we originally planned. We took this decision after we received one particular vulnerability report that highlighted a rather significant flaw.

We will ship a new version with this problem removed, together with twenty-one other albeit less serious security vulnerabilities addressed.

## Severity HIGH

In the curl project we only assign one of the four different  severity levels on all CVEs we report (LOW, MEDIUM, HIGH or CRITICAL), as we basically [don’t believe in CVSS scoring](https://daniel.haxx.se/blog/2025/01/23/cvss-is-dead-to-us/).  We have only published two CVEs with severity HIGH since 2021, the most recent one being [CVE-2023-38545](https://curl.se/docs/CVE-2023-38545.html); that could lead to a heap buffer overflow.

Now we are about to release another one: CVE-2026-92392.

## All info will be revealed next week

All details about CVE-2026-92392 will become public in the European morning of October 14, 2026 in synchronization of the release of curl 8.23.0 which of course will have this problem fixed.

We will ship updated [Rock-solid curl](https://rock-solid.curl.dev/) versions in sync with this.

For the safety and security of curl users everywhere (and frankly, all the infrastructure that uses curl), no details of this flaw will be made public before this date.

We will alert the distros@openwall mailing list and paying curl support customers about this problem (and the associated fix) ahead of time.

I will follow-up with a separate blog post after October 14 to describe this flaw in detail. How it can be triggered, why it isn’t quite the end of the world and what we do in curl to fix this and similar classes of problems.
