curl / Docs / Vulnerability table / 8.12.1 vulnerabilities

Vulnerabilities in curl 8.12.1

curl version 8.12.1 was released on February 13 2025

It has the following 4 published security problems.

FlawFrom versionTo and including
predictable WebSocket mask8.11.08.15.0
Out of bounds read for cookie path7.31.08.15.0
No QUIC certificate pinning with wolfSSL8.5.08.13.0
QUIC certificate check skip with wolfSSL8.8.08.13.0

Further details

CVE data for 8.12.1 provided as JSON.

Changelog for curl 8.12.1

See vulnerability summary for the previous release: 8.12.0 or the subsequent release: 8.13.0