curl / Docs / Vulnerability table / 8.5.0 vulnerabilities

Vulnerabilities in curl 8.5.0

curl version 8.5.0 was released on December 6 2023. The following 4 security problems are known to exist in this version.

FlawFrom versionTo and including
TLS certificate check bypass with mbedTLS8.5.08.6.0
HTTP/2 push headers memory-leak7.44.08.6.0
Usage of disabled protocol7.85.08.6.0
OCSP verification bypass with TLS session reuse8.5.08.5.0

CVE data for 8.5.0 provided as JSON.

Changelog for curl 8.5.0

See vulnerability summary for the previous release: 8.4.0 or the subsequent release: 8.6.0