Skip to main content

Search

Items tagged with: Curl


New input field added to Hackerone submissions for #curl
#curl


reporter submits a hackerone report against #curl that includes "a crash in function NNN" with lots of complicated details.

With the little detail that function NNN was made up and does not exist in real code.

#curl


🔧 Curl is your best friend when testing webhooks! 🔧

Whether you're debugging or just need a quick test, curl has you covered.

#Webhooks #Curl #WebDevelopment #TechTips #Debugging #Automation


We got this "HIGH security problem" reported for #curl earlier today:

"The -o / --output parameter in cURL does not restrict or sanitize file paths. When passed relative traversal sequences (e.g., ../../), cURL writes files outside the current working directory, allowing arbitrary file overwrite. In automated or privileged environments (CI/CD, root containers), this leads to Remote Code Execution (RCE), privilege escalation, and supply chain risk."

Never a dull moment.

#curl


Don't forget to sign up for OpenInfra Forum on May 22 in #Stockholm to come and hear me blab about #curl. Or just extract some stickers from me and listen to the others instead.

https://www.meetup.com/openinfra-user-group-sweden/events/306139678/


Live the bleeding edge life and take curl-8.14.0-rc1 for a test spin for us!

Thanks to users testing our rc builds, we can reduce the regression risk once we ship the actual *real* release on May 28. Today I shipped the rc1. There will be two more rc builds before the release.

https://curl.se/rc/

Thanks for flying #curl

#curl


Welcome Andrei Florea as #curl commit author 1373: https://github.com/curl/curl/pull/16964
#curl


I'm not saying it is healthy but I seem to have (checks notes) *six* presentations for #curl up this coming weekend.

Currently they sum up to 182 slides.

#curl


My secret to doing these "this date on YYYY" posts is that I have a document with 300 events on 200 dates from #curl history in calendar date order.
#curl


I don't have the "adoption date" of #curl into other distros, so if you can dig out some I'd be happy to take notes!
#curl


On this day in 1998, we shipped #curl 4.3.

It would take another year until it was first adopted into #Debian.


Welcome NeimadTL as #curl commit author 1372: https://github.com/curl/curl/pull/17233
#curl


This ordinary Tuesday? Two. Two AI slop security reports arrived to #curl. So far.
#curl


this is for my discussion session 100-year-curl at #curl up this coming weekend
#curl


What would YOU say are the biggest risks or obstacles that will prevent #curl as a project and product to live until its 100th birthday 2096?
#curl


Welcome Andreas Westin as #curl commit author 1370: https://github.com/curl/curl/pull/17186
#curl


I'm pondering adding a --location-mode flag to #curl and I could use your feedback!

https://github.com/curl/curl/pull/16543

#curl


After six years and 500+ reports to the #curl bug-bounty, the stats that might be the coolest:

Average time to first response: 1h
Median time to first response: 0h

I read this like we replied to more than half of the reports within 30 minutes.

(and yeah, maybe HackerOne should offer higher time resolution)

#curl


Slide 108 in my "state of curl" WIP slideset for #curl up 2025
#curl


First private email: hello, can you help me use libcurl to do [bla bla bla]

Me: sure, but unless you get a support contract you need to ask the question in a public #curl forum or mailing list.

Second private email: [inserts a long detailed question]

Me: OH HUMANITY

#curl


Ten years ago #curl visited the Nasdaq tower in New York

https://daniel.haxx.se/blog/2015/04/24/curl-on-the-nasdaq-tower/

#curl


How the CNA thing is working out for #curl

https://daniel.haxx.se/blog/2025/04/24/how-the-cna-thing-is-working-out/

#curl


Welcome Jochen Sprickerhof as #curl commit author 1369: https://github.com/curl/curl/pull/17156
#curl


Updated #curl bug bounty stats, six years in:

520 reports
78 confirmed security vulnerabilities
104 "informative" reports, bugs that weren't vulnerabilities
11 marked as "AI slop"

The rest were just different kinds of not applicable. Some more crazy than others.

The latest confirmed curl vulnerability (CVE-2025-0725) was reported 90 days ago.

There is currently zero issues in our queue.

https://curl.se/docs/bugbounty.html

#curl


Welcome Helmut Grohne as #curl commit author 1368: https://github.com/curl/curl/pull/17159
#curl


@kiyo I don't know and I don't care that much. If people want it added there it will be added. For users such as #curl, we add things like DoH ourselves anyway and it would be hard to use any such provided by c-ares because of the "different layer" it works on.


tell me, what info/trend/data should I dig up or extract and include in my "state of #curl" talk at curl up in less than two weeks?

Here's the two hour talk I did last year:

https://youtu.be/1X3IP-pvKTY?si=mGAqufEzPnaoEvPs

#curl


I compared #curl today vs curl 8 years ago on malloc count + memory use to download a single 512MB file over cleartext HTTP:

129 mallocs, which is exactly the same.

Maximum allocated now: 135566. 17,681 bytes *less* than eight years ago.

Not everything has to go bloat over time I suppose.

And here's the old blog post: https://daniel.haxx.se/blog/2017/04/22/fewer-mallocs-in-curl/

#curl


Welcome Max Eliaser as #curl commit author 1367: https://github.com/curl/curl/pull/17105
#curl


One year anniversary for the #curl pillow "curl is just the hobby"

https://daniel.haxx.se/blog/2024/04/22/curl-is-just-the-hobby/

#curl


Starting with the next #curl release (8.14.0), the #wcurl script will come bundled. To make it easier for everyone to do more curl better of course.


The AI-slop-security-vulnerability-counter for #curl was bumped twice this week.
#curl


Welcome Brian Chrzanowski as #curl commit author 1366: https://github.com/curl/curl/pull/16744 (thanks to Calvin Ruocco who made the PR)
#curl


Look, @icing now has his name on more than 1/4 of the lines of #curl production source code:


Every topic I usually blab about here in a single weekend in Prague? That's basically #curl up 2025. Consider yourself invited. Only two weeks away now.

https://github.com/curl/curl-up/wiki/2025

#curl