You mean a "race condition", not timing attack.
There are lots of ways you can get bad data from a given server over curl, even if using HTTPS and the attacker does not have full control over the server:
* Typo in URL and typosquatter sends you whatever commands they want
* XSS in server-side scripts leads to injection of commands via unescaped tags
There may be others I haven't thought of. Perhaps a DNS glue record can be used to inject shell metacharacters where the server has an error handler that reports the client hostname? The fact that any of these are even possible shows how fragile this mechanism is.