Summary
curl 8.21.0 fixed six vulnerabilities reported by Joshua Rogers of AISLE Research. The set includes a SASL double-free, password and authorization-state leaks, and protocol-state mistakes accumulated across different periods of the curl codebase.
The oldest issue in the campaign predates modern AI tooling by many years; the relevant ledger fact is that an AI-native security platform participated in its 2026 discovery and disclosure.
Severity boundary
AISLE’s registry assigns more aggressive scores to some rows. Bugflation uses curl’s own classifications: the cluster is Medium at its highest upstream-rated member, with several Low entries.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.