Wu Says learned that SlowMist's Chief Information Security Officer 23pds tweeted that Curl has fixed 18 security vulnerabilities, involving issues such as authentication bypass, memory safety, and host verification, with one libcurl vulnerability having existed for about 25 years. The related risks affect not only the curl command line but also a wide range of applications, SDKs, containers, firmware, gateways, and CI/CD environments that rely on libcurl. It is recommended to upgrade curl/libcurl as soon as possible, and check whether an older version of libcurl is in use, with special attention to mTLS, proxy authentication, and connection reuse scenarios.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 2
  • Repost
  • Share
Comment
Add a comment
Add a comment
StardustUnderTheGlassDome
· 10h ago
A vulnerability that existed for 25 years was only discovered now; supply chain security should never be taken lightly.
View OriginalReply0
Lightning-FastComposure
· 10h ago
Already upgraded, thanks for the reminder.
View OriginalReply0
  • Pinned