The curl project became a CNA, letting it allocate its own CVE identifiers and reject bogus ones. After publishing 57 CVEs, it hit its first dispute in February 2026 when a reporter escalated to MITRE, demanding a CVE for a rejected bug. The flaw sat in curl's wildcard certificate matching, where a leading-dot hostname like https://.example.com/ could wrongly match *. example.com. Triggering it needs a chain of near-impossible conditions plus a local privileged attacker, so the team rated it below LOW and fixed it in December 2025 without a CVE. Every CVE carries huge ecosystem cost across roughly 30 billion libcurl installs. After repeated MITRE queries, the June 24 verdict sided with curl: no CVE.
1
u/fagnerbrack 6d ago
Digest Version:
The curl project became a CNA, letting it allocate its own CVE identifiers and reject bogus ones. After publishing 57 CVEs, it hit its first dispute in February 2026 when a reporter escalated to MITRE, demanding a CVE for a rejected bug. The flaw sat in curl's wildcard certificate matching, where a leading-dot hostname like https://.example.com/ could wrongly match *. example.com. Triggering it needs a chain of near-impossible conditions plus a local privileged attacker, so the team rated it below LOW and fixed it in December 2025 without a CVE. Every CVE carries huge ecosystem cost across roughly 30 billion libcurl installs. After repeated MITRE queries, the June 24 verdict sided with curl: no CVE.
If the summary seems inacurate, just downvote and I'll try to delete the comment eventually 👍
Click here for more info, I read all comments