One of the main upsides of Curl is that it doesn't pull in a dozen different libraries for every task at hand. The code footprint is small, the surface area for vulnerabilities is small and the reliability is high.
I disagree. Their NIH-syndrome and ancient practices seem to be a constant source of new CVE:s [1].