> curl 8.22.0
[AUTHOR: Daniel Stenberg]
[DATE: 02/09/2026 05:52]
[LANGUAGE: EN]
Welcome to this new release. Get it as always from https://curl.se.
If you rather want a security-patched older release branch, stay tuned for the follow-up Rock-solid curl announcement within a few days.
Release presentation
At 10:00 CEST (08:00 UTC) Daniel makes a live-streamed release presentation on Twich.
Numbers
the 276th release6 changes70 days (total: 10,887)302 bugfixes (total: 14,489)525 commits (total: 39,608)0 new public libcurl function (total: 100)4 new curl_easy_setopt() option (total: 312)4 new curl command line option (total: 278)85 contributors, 55 new (total: 3,786)43 authors, 29 new (total: 1,518)9 security fixes (total: 215)
Security
Associated with this release, we publish ten new CVEs. Nine of them are for curl and libcurl, and one is for wcurl.
CVE-2026-13608: OpenLDAP SASL authentication bypass
CVE-2026-18924: HTTP/2 server push UAF
CVE-2026-19931: Negotiate ambient user conn reuse
CVE-2026-80229: OpenSSL provider use-after-free
CVE-2026-80230: OpenSSL pinning bypass
CVE-2026-80231: native CA store conn reuse
CVE-2026-80255: secure cookie attribute bypass with tab
CVE-2026-82208: wolfSSL CA-cache hit overrides callback
CVE-2026-82209: domain-scoped PSL domain cookie
The wcurl one:
CVE-2026-80256: wcurl backslash bypass
Changes
added support for Apple GSS Framework
added API guards
new RFC 9421 HTTP Message Signatures support (experimental)
blocks NTLM fallback in SPNEGO negotiation
dropped support for TLS-SRP
added option to use Apple fast UDP
Coming removals
HTTP/2 Server Push
local crypto implementations
NTLM
SMB
Next
We plan the next curl release to happen at the end of October unless there are some bad regressions reported against 8.22.0.