The curl project released curl/libcurl 8.22.0, its 276th release, with 302 bug fixes and ten security advisories: nine affecting curl or libcurl and one affecting wcurl. The fixes address authentication bypasses, use-after-free conditions, certificate-validation and certificate-pinning bypasses, unsafe connection reuse, and cookie-policy bypasses. The release also adds experimental RFC 9421 HTTP Message Signatures support, prevents NTLM fallback during SPNEGO negotiation, adds Apple-platform support, and removes TLS-SRP support.
One advisory, CVE-2026-80256, is a medium-severity Windows path-traversal flaw in wcurl. Percent-encoded backslashes in a server-influenced output filename can be decoded, allowing a file to be written outside the directory selected by the user. Affected versions include wcurl bundled with curl 8.14.0 through 8.21.0 and standalone wcurl 2024.12.08 through 2026.01.05; remediation is to upgrade to curl 8.22.0 or wcurl 2026.08.30, apply the patch, explicitly set output filenames, or disable output-filename percent decoding.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Tenable published Nessus plugin 342615 to identify libcurl 7.64.1 through versions before 8.22.0 affected by CVE-2026-19931, a Negotiate-authenticated connection-reuse information-disclosure flaw. The version-based check does not directly test exploitability and reports no known public exploits.
The curl project released curl and libcurl 8.22.0, its 276th release, with 302 bug fixes and nine security fixes. It published ten CVEs covering curl, libcurl, and wcurl, including authentication bypasses, use-after-free flaws, certificate-pinning or validation bypasses, connection-reuse issues, cookie-policy bypasses, and CVE-2026-80256.
The standalone wcurl 2026.08.30 release fixed CVE-2026-80256, the percent-encoded-backslash path traversal issue affecting Windows users.
Researcher 1rhino2 reported CVE-2026-80256 to the curl project through HackerOne. The Windows-only flaw lets percent-encoded backslashes in output filenames result in a new attacker-controlled file being created outside the user-selected directory, subject to the invoking user's permissions.
The curl project received Martin Dukek's vulnerability report for CVE-2026-19931, involving reuse of a Negotiate-authenticated HTTP connection across ambient user identities. Stefan Eissing subsequently patched the issue.
Tenable published a Unix-focused assessment plugin for unpatched critical curl vulnerability CVE-2026-13608 on listed Ubuntu LTS and Debian releases. The plugin describes network-reachable exploitation requiring no privileges or user interaction and states that no known public exploits are available.
Tenable's Unix-focused plugin 342437 identifies unpatched CVE-2026-19931 in curl packages on listed Ubuntu LTS and Debian releases. The plugin rates the issue critical under CVSS v3.0 and states that no known exploits are available.
Tenable published Nessus plugin 342617 to identify libcurl 7.44.0 through versions before 8.22.0 affected by CVE-2026-18924, an HTTP/2 Server Push use-after-free that can occur during cleanup when handles share connections. The version-based detection does not actively test exploitation, and no known exploits were reported.
Tenable identified CVE-2026-82208 as an unpatched critical (CVSS 9.8) curl-package vulnerability affecting multiple Ubuntu LTS releases and Debian 13.0 and 14.0. The notice describes network-reachable exploitation without privileges or user interaction and reports no known exploits.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceseclists.org
Open sourcetenable.com
Open sourcecurl.se
Open sourcecybersecurity-help.cz
Open sourcecurl.se
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.