curl brings 8.23.0 forward to 14 October to fix CVE-2026-92392, rated HIGH by the curl project, plus 21 lower-severity vulnerabilities; details stay embargoed until release
curl lead developer Daniel Stenberg announced on 7 October 2026 that curl 8.23.0 will ship on 14 October 2026, a few weeks earlier than planned, because of one vulnerability report describing a significant flaw. The release fixes CVE-2026-92392, which the curl project rates HIGH (it uses its own LOW/MEDIUM/HIGH/CRITICAL scale and does not publish CVSS scores), together with 21 other, less serious vulnerabilities. It is only the third curl CVE rated HIGH since 2021; the last was CVE-2023-38545, a heap buffer overflow. No technical details will be published before the European morning of 14 October, when the advisory and the fixed release go out together. Linux distributions (via the distros@openwall list) and paying curl support customers are being told in advance. curl and libcurl are embedded in operating systems, containers, network appliances, cars and countless applications, so expect a long tail of vendor updates after the release. No exploitation is reported. Primary: the curl project lead's blog.
- Product
- curl and libcurl
- Versions
- Versions before 8.23.0 (affected range for CVE-2026-92392 not yet published)
- CVSS
- Not scored; curl project severity HIGH (CVE-2026-92392)
- Exploited in Australia?
- unknown
- Patch to
- curl/libcurl 8.23.0 (due 14 Oct 2026), or your OS or vendor's patched package. Now: inventory where curl and libcurl are bundled (base images, appliances, SDKs) so you can update quickly on release day.
Primary: Daniel Stenberg (curl lead developer) — Twenty-two pending curl vulnerabilities (7 Oct 2026) · Vendor: curl — security advisories index · CVE: CVE-2026-92392, CVE-2023-38545
