curl Will Ship 22 Vulnerability Fixes in 8.23.0 on October 14, One Rated HIGH
Software / news
curl Will Ship 22 Vulnerability Fixes in 8.23.0 on October 14, One Rated HIGH
Daniel Stenberg says CVE-2026-92392 is only the second HIGH-severity curl CVE since 2021. Details stay embargoed until the release.

The curl project will release version 8.23.0 on October 14, 2026 with fixes for 22 vulnerabilities, one of them rated HIGH severity. Daniel Stenberg, curl's lead developer, announced the batch in an October 7 blog post.
The HIGH one is CVE-2026-92392. The other 21 are rated lower. Stenberg's post gives no names, versions or bug classes for any of the 22.
What Stenberg has said about CVE-2026-92392
"All details about CVE-2026-92392 will become public in the European morning of October 14, 2026 in synchronization of the release of curl 8.23.0," the post says. Linux distributions on the distros@openwall list and paying support customers are told earlier.
Stenberg also wrote that "we decided to shorten the release cycle this time," pulling 8.23.0 forward after a serious report. He promised a follow-up post explaining the flaw and the fix.
That leaves nothing to patch yet. The practical task for anyone who ships curl or libcurl is to find where it is bundled, because the fix will land in a release inside a week.
How rare a HIGH is for curl
Stenberg's post says curl has "only published two CVEs with severity HIGH since 2021," the most recent being CVE-2023-38545, a heap buffer overflow. The curl security page lists 215 documented vulnerabilities in total, and shows CVE-2026-82209, CVE-2026-82208 and CVE-2026-80255 as recent entries, all rated Low.
| CVE | Date | Description on curl.se |
|---|---|---|
| CVE-2021-22901 | 2021-05-26 | TLS session caching disaster |
| CVE-2023-38545 | 2023-10-11 | SOCKS5 heap buffer overflow |
| CVE-2026-92392 | 2026-10-14 (planned) | Details embargoed |
The first two rows come from the curl security page, which lists both among HIGH entries. The third is the planned disclosure date from Stenberg's post.

What the sources do not say
Stenberg's post does not say how the 22 were found: no tool, no researcher and no count of reporters. It does not say which of them need a particular TLS backend or protocol. The curl security page carries its own note that many past flaws come from curl being written in C and that a memory-safe language might have prevented many of them.
For scale, the security page's visible entries show at least 24 curl CVEs already published in 2026. Our piece on CISA's three-day deadlines shows why a bundled library with a HIGH rating tends to matter more than its count suggests. A separate Atlassian advisory shows the other pattern, where one flaw hits every version.
What to do before the release
Stenberg's post names two groups with early access: distribution maintainers reached through distros@openwall, and paying support customers. Everyone else learns the details at the same moment as the public, on October 14.
Teams that vendor curl in a container image, a mobile SDK or a build toolchain are in the second group by default. They cannot patch ahead of time, so the useful preparation is an inventory of which builds link libcurl and which version each one carries.
What happens on October 14
curl 8.23.0 and the CVE-2026-92392 write-up are due together that morning, European time. Check what links against libcurl before then, so the update is a build and not a hunt.
Sources
More in Software
- 01REA Hits 15.7k Stars as an MCP Toolkit That Lets AI Agents Reverse-Engineer SoftwareThe MIT-licensed project wraps Ghidra, Hopper and IDA in 134 agent tools, and its own README says process capture is not a sandbox.
- 02God of War: Chains of Olympus Runs in a Browser Through Recompilation, Not EmulationThe psp-web-recomp repository translates PSP executables to WebAssembly and reports 60 fps, but only two games from one studio work.
- 03Margaret Hamilton, Who Led Apollo's Flight Software Team, Dies at 90MIT says her team's priority-driven design let the Apollo 11 landing proceed through a 1202 alarm; the code she signed off in 1969 is on GitHub.
- 04docker agent Runs YAML-Defined AI Agents From Any OCI Registry. Its README Says Nothing on SandboxingDocker Engineering's Apache-2.0 plugin ships pre-installed in Docker Desktop 4.63, but the repository shows no tagged release and a telemetry notice.