25 Year Old Curl Vulnerability Finally Patched
25 Year Old Curl Vulnerability Finally Patched in Record Security Release A security flaw that remained inside curl for more than 25 years has finally been patched as part of a record breaking curl security release. The vulnerability is tracked as CVE 2026 8932. It was first introduced in curl version 7.7, which was released on March 22, 2001. That makes it one of the oldest curl security issues ever reported. The flaw was fixed in curl 8.21.0 as part of a major security update that addressed 18 CVEs in a single release. For enterprises, this is more than an open source maintenance story. Curl is foundational internet infrastructure. It is used directly as a command line tool and indirectly through libcurl, the embedded transfer library used across operating systems, containers, CI/CD pipelines, package managers, SDKs, embedded products, automotive systems, and countless software platforms. A vulnerability in curl can therefore affect far more than the users who knowingly run the curl ...