Vulnerability
Published 2026-10-07
Verified 2026-10-08

curl brings 8.23.0 forward to 14 October to fix CVE-2026-92392, rated HIGH by the curl project, plus 21 lower-severity vulnerabilities; details stay embargoed until release

curl lead developer Daniel Stenberg announced on 7 October 2026 that curl 8.23.0 will ship on 14 October 2026, a few weeks earlier than planned, because of one vulnerability report describing a significant flaw. The release fixes CVE-2026-92392, which the curl project rates HIGH (it uses its own LOW/MEDIUM/HIGH/CRITICAL scale and does not publish CVSS scores), together with 21 other, less serious vulnerabilities. It is only the third curl CVE rated HIGH since 2021; the last was CVE-2023-38545, a heap buffer overflow. No technical details will be published before the European morning of 14 October, when the advisory and the fixed release go out together. Linux distributions (via the distros@openwall list) and paying curl support customers are being told in advance. curl and libcurl are embedded in operating systems, containers, network appliances, cars and countless applications, so expect a long tail of vendor updates after the release. No exploitation is reported. Primary: the curl project lead's blog.

Product
curl and libcurl
Versions
Versions before 8.23.0 (affected range for CVE-2026-92392 not yet published)
CVSS
Not scored; curl project severity HIGH (CVE-2026-92392)
Exploited in Australia?
unknown
Patch to
curl/libcurl 8.23.0 (due 14 Oct 2026), or your OS or vendor's patched package. Now: inventory where curl and libcurl are bundled (base images, appliances, SDKs) so you can update quickly on release day.

Primary: Daniel Stenberg (curl lead developer) — Twenty-two pending curl vulnerabilities (7 Oct 2026) · Vendor: curl — security advisories index · CVE: CVE-2026-92392, CVE-2023-38545

vulnerabilities network cloud