#22618 closed enhancement (fixed)
curl-8.18.0
| Reported by: | Joe Locash | Owned by: | zeckma |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New minor release.
Changelog: https://curl.se/ch/
This release fixes 6 CVE's:
- CVE-2025-15224: libssh key passphrase bypass without agent set
https://curl.se/docs/CVE-2025-15224.html
- CVE-2025-15079: libssh global known_hosts override
https://curl.se/docs/CVE-2025-15079.html
- CVE-2025-14819: OpenSSL partial chain store policy bypass
https://curl.se/docs/CVE-2025-14819.html
- CVE-2025-14524: bearer token leak on cross-protocol redirect
https://curl.se/docs/CVE-2025-14524.html
- CVE-2025-14017: broken TLS options for threaded LDAPS
https://curl.se/docs/CVE-2025-14017.html
- CVE-2025-13034: No QUIC certificate pinning with GnuTLS
Change History (12)
comment:2 by , 9 months ago
Looking at this a bit deeper, I think the only vulnerability that we're vulnerable to is CVE-2025-14819 in our default configuration, though some users might get hit by CVE-2025-13034. We use OpenLDAP for LDAP support, so as far as I know we shouldn't be affected by CVE-2025-14017. We could theoretically also get hit by CVE-2025-14524 but I don't know of any normal use cases that we have that use OAuth2 tokens
comment:3 by , 9 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:5 by , 9 months ago
It's hard for me to understand why there are over 400 changes to a package that has been around as long as this one. The previous release was November 2025. Perhaps they are trying to do too much in one application.
comment:6 by , 9 months ago
Fixed at commits
c6fbfb3662 Update to poppler-26.01.0. 05ad7dbebc Update to curl-8.18.0 (Security Update). e9ec3d89ff Update to libtasn1-4.21.0 (Security Update). d939395a16 Update to libjpeg-turbo-3.1.3.
comment:7 by , 9 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Leaving open for security advisory. Reassigning.
comment:8 by , 9 months ago
| Status: | new → assigned |
|---|
comment:9 by , 9 months ago
Thanks for not closing the security tickets before SA filing. It's appreciated!

AFAIK BLFS does not have libssh (not libssh2: they are different packages) and QUIC support at all. Thus I'm unsure if we should mention those three in SA.