Curl library security flaws revealed

Computer programming source code. Programming code abstract technology background of software developer and Computer script.
(Image credit: Shutterstock/BEST-BACKGROUNDS)

The Curl library is vulnerable to two flaws, one of which is “arguably the most critical security flaw identified in curl in recent history,” experts have warned.

For the uninitiated, Curl is an open source command-line tool used to transfer data with URL syntax. It supports multiple network protocols, including SSL, TLS, HTTP, FTP, SMTP, and more. 

It is mostly used by developers and system administrators prevalently to interact with APIs, download files, and create automated workflows.

Withholding details

Saeed Abbasi, Product Manager with Qualys’ Threat Research Unit, published a blog post explaining the flaws and the upcoming fix. In the announcement, he said that the two vulnerabilities being addressed are tracked as CVE-2023-38545 and CVE-2023-38546. The first one is labeled as high-severity, and affects both libcurl and the curl tool. The second one is low-severity, and only impacts libcurl.

Given that the fix is yet to be released, the researchers did not want to share any more details. Among other things, they couldn’t say which versions were vulnerable, as that would help pinpoint the problematic areas quite accurately.

In a GitHub discussion, maintainer Daniel Stenberg only said that the flaws affect "last several years" of versions. That’s “as specific as I can get” he said. "Sure, there is a minuscule risk that someone can find this (again) before we ship the patch, but this issue has stayed undetected for years for a reason," Stenberg added.

The update is expected to be released on October 11 this year, when Curl will hit version 8.4.9, Abbasi confirmed. "Organizations should urgently inventory and scan all systems utilizing curl and libcurl, anticipating identifying potentially vulnerable versions once details are disclosed with the release of Curl 8.4.0 on October 11."

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Cyber-security
Top file-sharing tools are being hit by security attacks once again
WordPress
Another top WordPress plugin found carrying critical security flaws
Data leak
Zyxel, ProjectSend, CyberPanel vulnerabilities actively exploited, so patch now
Representational image depecting cybersecurity protection
OpenSSH vulnerabilities could pose huge threat to businesses everywhere
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Top WordPress plugins found to have some serious security flaws, so make sure you're protected
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection