﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
22618	curl-8.18.0	Joe Locash	zeckma	"New minor release.

Changelog: https://curl.se/ch/

This release fixes 6 CVE's:

 - CVE-2025-15224: libssh key passphrase bypass without agent set
https://curl.se/docs/CVE-2025-15224.html

 - CVE-2025-15079: libssh global known_hosts override
https://curl.se/docs/CVE-2025-15079.html

 - CVE-2025-14819: OpenSSL partial chain store policy bypass
https://curl.se/docs/CVE-2025-14819.html

 - CVE-2025-14524: bearer token leak on cross-protocol redirect
https://curl.se/docs/CVE-2025-14524.html

 - CVE-2025-14017: broken TLS options for threaded LDAPS
https://curl.se/docs/CVE-2025-14017.html

 - CVE-2025-13034: No QUIC certificate pinning with GnuTLS
https://curl.se/docs/CVE-2025-13034.html
"	enhancement	closed	elevated	13.0	BOOK	git	medium	fixed		
