curl 8.21.0

Release presentation At 09:00 UTC (11:00 CEST) today I will do a traditional live-streamed release presentation of this release over on my Twitch channel. Numbers the 275th release6 changes56 days (total: 10,817)276 bugfixes (total: 14,187)531 commits (total: 39,077)0 new public libcurl function (total: 100)0 new curl_easy_setopt() option (total: 308)1 new curl command line option (total: … Continue reading curl 8.21.0 →

daniel.haxx.se

We publish 18 new #curl vulnerabilities in association with this release. They are all listed in this email. 4 MEDIUM, 14 LOW.

https://curl.se/mail/lib-2026-06/0026.html

curl: [SECURITY ADVISORIES] for curl 8.21.0

I hope this "flood" explains why we feel we need a summer of bliss after this.

https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/

curl summer of bliss

The curl project will not accept or otherwise handle any vulnerability reports during the month of July 2026. We call it the curl summer of bliss. curl's submission form on Hackerone will be paused starting July 1, 2026. Summer of bliss starts: July 1, 2026. 00:00 CEST Submissions resume: August 3 2026. 09:00 CEST The … Continue reading curl summer of bliss →

daniel.haxx.se

The original hackerone reports for all these new vulnerabilities are about to get disclosed as well over the next few days.

You should be able to track and see our work on every security issue from the start to the end.