Curl 8.4.0 will be released on October 11 – a fix for a severity HIGH CVE
twitter.com
twitter.com
https://github.com/curl/curl/discussions/12026
The CVEs:
CVE-2023-38545: severity HIGH (affects both libcurl and the curl tool)
CVE-2023-38546: severity LOW (affects libcurl only, not the tool)
I really wish people would just stop posting submissions to twitter at this point.
I fully agree. You can also replace twitter.com with nitter.net
We just did a quick snapshot of a small chunk of a customer's environment and they're running 10 different versions of curl in like 15 different images :(