Search Articles

Search Results: curl

Inside curl’s Security Pipeline: How 600+ Vulnerabilities Navigate from Report to CVE

Inside curl’s Security Pipeline: How 600+ Vulnerabilities Navigate from Report to CVE

curl, the ubiquitous data transfer tool, processes 3-4 security reports weekly through a meticulously orchestrated workflow involving seven dedicated maintainers. This exclusive breakdown reveals how low-risk fixes hide in plain sight while critical patches follow a 48-hour secrecy rule before public release. The process exemplifies open-source security rigor at scale.
curl 8.16.0 Turbocharges Connection Racing with Parallel Happy Eyeballs v3-Inspired Algorithm

curl 8.16.0 Turbocharges Connection Racing with Parallel Happy Eyeballs v3-Inspired Algorithm

curl's latest update implements groundbreaking parallel connection racing, dynamically initiating IPv4, IPv6, and QUIC handshakes in staggered 200ms intervals to slash connection times. This evolution of the Happy Eyeballs algorithm tackles modern networking challenges, including QUIC integration and slow DNS responses. The overhaul demonstrates curl's relentless optimization for real-world network resilience.

Critical Heap Corruption Flaw Discovered in curl's SOCKS5 Proxy Handling

A severe vulnerability (CVE-2023-38545) in curl and libcurl allows remote attackers to trigger heap corruption when communicating through a malicious SOCKS5 proxy. This high-severity flaw, affecting versions 7.69.0 to 8.3.0, poses significant risks to applications using SOCKS proxies with automatic redirects or hostname length manipulation.