On October 7, Daniel Stenberg posted a quiet but consequential update: curl 8.23.0 ships October 14 with 22 CVEs, including one rated HIGH. CVE-2026-92392 is only the third HIGH-severity curl vulnerability since 2021. Details are embargoed until the release day. Set a calendar reminder for October 14 and get your update procedures ready now.
What We Know About CVE-2026-92392
Very little, intentionally. Stenberg confirmed it is HIGH severity and will be fully disclosed in the European morning of October 14, synchronized with the 8.23.0 release. Before that date, only subscribers to the distros@openwall mailing list and paying curl support customers receive advance notice. That is the responsible disclosure process working as designed.
For context: the previous HIGH-severity curl CVE was CVE-2023-38545 in October 2023, a SOCKS5 heap buffer overflow that Stenberg called “probably the worst curl security flaw in a long time.” It required specific conditions to exploit — a SOCKS5h connection, a small negotiation buffer, a delayed server reply — but the HIGH rating reflects the potential impact when those conditions are met. The curl team uses that rating deliberately and rarely. This is only the third time since 2021 they have reached for it.
The other 21 CVEs in 8.23.0 are rated lower. The release cycle was shortened specifically because of CVE-2026-92392 — the team received the report and decided to ship a few weeks early rather than wait. That alone tells you something about their assessment of the risk.
Why curl Vulnerabilities Deserve Immediate Attention
curl runs on more than 30 billion devices. That figure is not a marketing estimate — it is the lower bound. curl ships with every Linux distribution, every macOS installation, and most Docker base images. libcurl is embedded in Python’s urllib internals, PHP, Go, Ruby, and hundreds of applications that never mention curl in their documentation.
Seven volunteer maintainers manage this entire security surface. When a HIGH-severity CVE lands in curl, the exposure window is not a few target systems — it is effectively every internet-connected server in production until patches propagate.
This is also the second unusually large release in 2026. The 8.21.0 release earlier this year patched 18 vulnerabilities, a record at the time, including a 25-year-old flaw in libcurl present since curl 7.7 (March 2001). That flaw was discovered using AI-assisted security tooling — a different story than the AI slop problem that killed curl’s bug bounty. Both are real; only one is useful.
Update Your Systems — By Platform
Do not wait for your operating system’s package manager to distribute the update. Downstream packaging lags by days to weeks on critical patches. On October 14, update directly.
Check your current version first:
curl --version
You should see 8.22.0. After October 14, you want 8.23.0.
macOS (Homebrew):
brew install curl
export PATH="/opt/homebrew/opt/curl/bin:$PATH" # add to ~/.zshrc
Ubuntu / Debian:
sudo apt update && sudo apt upgrade curl libcurl4
RHEL / Fedora:
sudo dnf update curl
Docker: Update any Dockerfiles or Kubernetes manifests using curlimages/curl. The :8.23.0 tag will be available on October 14. Check base images — Alpine, Ubuntu, and Debian images all bundle curl and will roll updates over the days following the release. If you use Renovate or Dependabot, enable automatic Docker tag updates.
CI/CD pipelines: Any pipeline step that calls curl directly uses the runner’s installed version. Cloud runners typically update base images automatically; self-hosted runners require a manual upgrade.
The AI Slop Arc Ends With Real CVEs
There is an uncomfortable throughline here. In January 2026, curl shut down its HackerOne bug bounty because AI-generated reports had overwhelmed the team. By mid-2025, the confirmation rate for vulnerability reports dropped below 5% — most submissions were LLM-generated hallucinations about non-existent code paths. In July 2026, the team took a full month off from processing external reports.
None of that made the real vulnerabilities go away. Twenty-two CVEs are shipping on October 14. One of them is HIGH severity. The AI slop was not a security problem — it was a human-cost problem that diverted maintainer attention from the actual security debt accumulating underneath it.
After October 14, watch for Stenberg’s follow-up post explaining CVE-2026-92392 in full. That is when the patch-or-mitigate decision becomes fully informed. Until then: know what version of curl you are running, know where it appears in your stack, and have the update ready to execute. The curl vulnerability history page will be updated the same morning.













