Skip to content

Upgrade curl to curl-8_21_0 (CVE-2026-8924, CVE-2026-9079) - #46

Closed
fadedreamz wants to merge 540 commits into
masterfrom
cve/curl-curl-8_21_0
Closed

Upgrade curl to curl-8_21_0 (CVE-2026-8924, CVE-2026-9079)#46
fadedreamz wants to merge 540 commits into
masterfrom
cve/curl-curl-8_21_0

Conversation

@fadedreamz

Copy link
Copy Markdown

Automated curl upgrade to curl-8_21_0 for CVE-2026-8924, CVE-2026-9079.

Merged upstream tag into master on branch cve/curl-curl-8_21_0.
Files changed: 1223.

Opened by cve-libcurl-updater. Do not auto-merge — human review required.

vszakats and others added 30 commits June 2, 2026 15:31
- Explain to contributors that though AI use is acceptable they must
  not file unless they can understand and explain their work without AI.

Assisted-by: Viktor Szakats

Ref: curl#21792

Closes curl#21801
- Refactor CA file reading to use the typical fopen/fread instead of
  CreateFile/ReadFile.

Closes curl#21773
- fix GnuTLS function name reference in `Curl_gtls_shared_creds_create()`
  error message.
  Spotted by GitHub Code Quality.
- unfold a line.
- in `Curl_gtls_verifyserver()`:
  - report the failure of `gnutls_x509_crt_import()`.
    Spotted by GitHub Code Quality.
  - fix a minor inconsistency in error strings.
  - drop redundant NULL checks for `config->issuercert`.

Closes curl#21850
Reported-by: zhanhb on github
Ref: curl#21847
Closes curl#21851
Move QUIC related implementations into the vquic directory. Rename
files that implement a connection filter accordingly.

Closes curl#21848
- updates `actions/labeler` from 6.0.1 to 6.1.0
- updates `github/codeql-action` from 4.35.2 to 4.36.0

Closes curl#21852
- introduce a few static helper functions
- simplify the bad octet checks
- simplify the too long cookie/value check

Closes curl#21854
- introduce helper functions
- remove #ifdef'ed debug code

Closes curl#21855
- make file_url() a separate function that returns a file:// URL
- group the checks that need scheme info

Closes curl#21856
These fail without cookie support.

Closes curl#21858
- Change link from archive.org back to hollywood-mal.com since the site
  is up and running.

Closes curl#21862
With a flood of zero lenght UDP packets to curl, the receive loop might
run longer than intended to. Count such packets against the max to
terminate the loop as intended.

URL: https://hackerone.com/reports/3783438
Reported-by: vectorqueue on hackerone
Closes curl#21869
Supported since libssh2 v1.2.5. Replacing `libssh2_knownhost_add()`,
which was deprecated in that same version.

The new API supports a comment field.

Ref: libssh2/libssh2#1977

Closes curl#21866
To support building with `LIBSSH2_NO_DEPRECATED` macro defined, a future
libssh2 that may have dropped these macros.

Ref: libssh2/libssh2#1977

Closes curl#21867
Spotted by GitHub Code Quality

Closes curl#21877
- fix typos.
- badword: add two new words.
- cpp: drop parentheses from standalone `#if` expressions.
- libssh: vertical-align comment block with others.
- clang-format.

Closes curl#21880
- Specify that the content is base64 encoded, rather than rely on
  auto-detect.

- Remove unnecessary sanity check of the returned content type.

Closes curl#21760
When the struct is passed to the CURLOPT_CHUNK_BGN_FUNCTION callback,
clear the pointer if the provided data is not a symlink.

Closes curl#21884
Whack the times reported for a transfer (see
https://curl.se/libcurl/c/curl_easy_getinfo.html#TIMES) into order for
all variations of up-/download, http/ftp etc. Make sure they are
reported in the documented order.

There is still the *possibility* of PRETRANSFER being longer then
POSTTRANSFER, if a server sends a response before an upload is done.
POST is the time the first response byte is received, and PRE is the
time the last byte was sent by curl.

This may happen with more likelihood on HTTP/2 and 3 for a server
rejected upload. But for successful uploads, the answer will almost over
come afterwards.

Undo the previous twists in lib500.c tests, adjust pytest timeline
checks.

Fixes curl#21828
Reported-by: BazaarAcc32 on github
Closes curl#21843
This option should not be used.

Closes curl#21886
icing and others added 21 commits June 22, 2026 10:12
Give the libssh2 infof() messages a common format, add/clarify some to
make the connect/authentication flow more clear.

Closes curl#22101
Fixes curl#22105
Reported-by: av223119 on github
Closes curl#22109
Reported by GitHub Code Quality

Follow-up to 0095f98 curl#15250

Closes curl#22125
Just a tidy-up. Logic remains identical.

Spotted by GitHub Code Quality

Follow-up to a867314 curl#16382

Closes curl#22126
To avoid dereferencing in the function if `CURL_BLOB_COPY` is set, or
outside of the function if unset.

Reported-by: netspacer.research

Closes curl#22129
When trying to detect ipv6 addresses, ipv4 addresses were also
flagged as ipv6.

Add test2413 to check.

Closes curl#22134
```sh
git grep -w ca | grep -v -E -i 'ca[;"=/()%_.-]' | grep -v -E -i '[*$"=/()%_.-]ca'
```

Closes curl#22135
The buffer is freed on the next instruction via `Curl_meta_remove()`'s
destructor.

Reported-by: netspacer.research

Follow-up to 1ebd92d curl#16384

Closes curl#22133
Based on CI runs:
DragonFlyBSD: https://github.com/curl/curl/actions/runs/27978506617/job/82802332910 (autotools)
MidnightBSD: https://github.com/curl/curl/actions/runs/27977103321/job/82797523470 (cmake)

Also readd DragonFly BSD to GHA/non-native, but keep it commented.

Closes curl#22138
It's the final/stable image name and it's shipping with VS2026 now.

Ref: actions/runner-images#14017
Follow-up to b023941 curl#21713

Closes curl#22139
Also put the version number in quotes to avoid GHA altering the number
into `0.68` (without rightmost zero) and ending up storing that in the
`FIL_C_VERSION` env.

Hopefully Renovate will honor this on future bumps.

Do the same for the rest of `x.y` format version numbers.

Fixing:
```
env:
[...]
    FIL_C_VERSION: 0.68
```
Ref: https://github.com/curl/curl/actions/runs/28006009260/job/82920767558?pr=22142#step:5:16

Fixes curl#22142

Closes curl#22143
By using quotes a user name can have a space in netrc

Closes curl#22147
- add autotools jobs for MidnightBSD, NetBSD, OpenBSD.
  Takes under 3 minutes per new job, under +6m in total.
  - comment out MidnightBSD to save CI time.
  - to make them as fast as possible, skip building tests and examples,
    and omit libidn2, openldap dependencies.
- add DragonFly BSD cmake job, which finally works.
  (keep it commented out since the package server fails frequently.)
- do `mport index/upgrade` to make MidnightBSD autotools builds work.
- rework filtering MidnightBSD package manager's excessive log output.
- fixup OpenBSD autotools job to uninstall system curl to avoid linking
  against it (and breaking debug builds).
- make OpenBSD package manager commands non-interactive.
- specify install packages for each matrix entry.
- make autotools build step verbose (to ease debugging).
- add link to DragonFly BSD package repo.
- bump cross-platform-actions from 1.1.0 to 1.3.0.
- bump FreeBSD 15.0 to 15.1.
- bump OpenBSD to 7.7 to 7.9.
  This did not go well last time with 7.8, let's see with 7.9.
  Ref: 8d00e28 curl#19372
  Ref: c3b890b curl#19368
- sync test-skipper keywords with rest of workflows.
- drop installing impacket. It was unused.
  (also a slow install with many dependencies)

The original motivation was to prepare fixing OpenBSD's (and possibly
other platforms) `getaddrinfo()` thread-safety check.
Ref: curl#22138 (comment)

Closes curl#22145
@@ -2,8 +2,8 @@
#
# SPDX-License-Identifier: curl

cryptography==46.0.7
filelock==3.25.2
cryptography==48.0.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cycode: Security vulnerabilities found in newly introduced dependency.

Ecosystem PyPI
Dependency cryptography
Dependency Paths cryptography 48.0.1
Direct Dependency Yes
Development Dependency No

The following vulnerabilities were introduced:

GHSA CVE Severity Fixed Version
GHSA-g6cj-pr64-35w5 CVE-2026-69247 HIGH 50.0.0

Highest fixed version: 50.0.0

Description

Detects when new vulnerabilities affect your dependencies.

Tell us how you wish to proceed using one of the following commands:

Tag Short Description
#cycode_vulnerable_package_fix_this_violation Fix this violation via a commit to this branch
#cycode_ignore_manifest_here <reason> Applies to this manifest in this request only

⚠️ When commenting on Github, you may need to refresh the page to see the latest updates.

@fadedreamz fadedreamz closed this Sep 3, 2026
@fadedreamz
fadedreamz deleted the cve/curl-curl-8_21_0 branch September 3, 2026 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.