Package curl: Information

    Source package: curl
    Version: 8.18.0-alt1
    Build time:  Jan 10, 2026, 01:46 PM
    Report package bug
    Home page: https://curl.se/

    License: MIT
    Summary: Gets a file from a FTP, GOPHER or HTTP server
    Description: 
    Curl is a client to get documents/files from servers, using any of the
    supported protocols. The command is designed to work without user
    interaction or any kind of interactivity.
    
    Curl offers a busload of useful tricks like proxy support, user
    authentication, ftp upload, HTTP post, file transfer resume and more.

    List of RPM packages built from this SRPM:
    curl (riscv64)
    curl-debuginfo (riscv64)
    libcurl (riscv64)
    libcurl-debuginfo (riscv64)
    libcurl-devel (riscv64)

    Maintainer: Anton Farygin


      1. /proc
      2. /usr/bin/stunnel
      3. apache2-devel
      4. apache2-httpd-worker
      5. apache2-mod_http2
      6. apache2-mod_ssl
      7. caddy
      8. gnutls-utils
      9. groff-base
      10. libbrotli-devel
      11. libgnutls-devel
      12. libgnutls30
      13. libgsasl-devel
      14. libidn2-devel
      15. libkrb5-devel
      16. libldap-devel
      17. libnettle-devel
      18. libnghttp2-devel
      19. libnghttp2-tools
      20. libnghttp3-devel
      21. libngtcp2-devel >= 0.15.0
      22. libpsl-devel
      23. libssh2-devel
      24. libzstd-devel
      25. openssh-clients
      26. openssh-server
      27. perl(Digest/SHA.pm)
      28. perl(Memoize.pm)
      29. pytest3
      30. python3-base
      31. python3-module-cryptography
      32. python3-module-filelock
      33. python3-module-psutil
      34. python3-module-pytest-xdist
      35. vsftpd
      36. zlib-devel

    Last changed


    Jan. 9, 2026 Anton Farygin 8.18.0-alt1
    - 8.17.0 -> 8.18.0
    - Fixes:
      * CVE-2025-15224: libssh key passphrase bypass without agent set
      * CVE-2025-15079: libssh global known_hosts override
      * CVE-2025-14819: OpenSSL partial chain store policy bypass
      * CVE-2025-14524: bearer token leak on cross-protocol redirect
      * CVE-2025-14017: broken TLS options for threaded LDAPS
      * CVE-2025-13034: No QUIC certificate pinning with GnuTLS
    Nov. 5, 2025 Anton Farygin 8.17.0-alt1
    - 8.16.0 -> 8.17.0
    Sept. 10, 2025 Anton Farygin 8.16.0-alt1
    - 8.15.0 -> 8.16.0 (Fixes:  CVE-2025-10148, CVE-2025-9086)