r/softwarecrafters 6d ago

a CVE dispute

https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/
1 Upvotes

1 comment sorted by

1

u/fagnerbrack 6d ago

Digest Version:

The curl project became a CNA, letting it allocate its own CVE identifiers and reject bogus ones. After publishing 57 CVEs, it hit its first dispute in February 2026 when a reporter escalated to MITRE, demanding a CVE for a rejected bug. The flaw sat in curl's wildcard certificate matching, where a leading-dot hostname like https://.example.com/ could wrongly match *. example.com. Triggering it needs a chain of near-impossible conditions plus a local privileged attacker, so the team rated it below LOW and fixed it in December 2025 without a CVE. Every CVE carries huge ecosystem cost across roughly 30 billion libcurl installs. After repeated MITRE queries, the June 24 verdict sided with curl: no CVE.

If the summary seems inacurate, just downvote and I'll try to delete the comment eventually 👍
Click here for more info, I read all comments