daniel.haxx.se
Read post

a CVE dispute

Daniel Stenberg recounts curl's first CVE dispute since the project became a CNA (CVE Numbering Authority). A reporter submitted a bug involving wildcard certificate matching when a hostname has a leading dot — an illegal DNS name requiring a local attacker and a very specific chain of conditions to exploit. The curl team fixed the bug but declined to assign a CVE, classifying it as 'lower than LOW' severity. The reporter escalated to MITRE, which contacted the curl team three times over several months. On June 24, MITRE's TL-Root sided with curl, confirming no CVE would be assigned. The post also explains the real-world cost of CVEs given libcurl's ~30 billion installs, and why the team takes care not to trigger unnecessary security churn across the ecosystem.

    #security#curl
Jun 24•7m read time•From daniel.haxx.se
Post cover image
Table of contents
57 CVEsAssessLower than LOWThe cost of a CVEThe disputeHostname with a leading dotLower than LOWAgain in MayAgain in JuneVerdict
34.4K Impressions
daniel.haxx.se's image
daniel.haxx.se

126 Followers

•

1.5K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard