]> git.ipfire.org Git - thirdparty/curl.git/commitdiff
RELEASE-NOTES: synced master
authorDaniel Stenberg <daniel@haxx.se>
Thu, 30 Jul 2026 07:12:28 +0000 (09:12 +0200)
committerDaniel Stenberg <daniel@haxx.se>
Thu, 30 Jul 2026 07:12:28 +0000 (09:12 +0200)
RELEASE-NOTES

index b750535fa1d20c173732006a6294a1b17b54eeee..8c709a35d39a2c8de224cb224e7b3b8f54ad5cdb 100644 (file)
@@ -4,15 +4,17 @@ curl and libcurl 8.22.0
  Command line options:         278
  curl_easy_setopt() options:   312
  Public functions in libcurl:  100
  Command line options:         278
  curl_easy_setopt() options:   312
  Public functions in libcurl:  100
- Authors:                      1500
- Contributors:                 3753
+ Authors:                      1502
+ Contributors:                 3756
 
 This release includes the following changes:
 
  o gssapi: add support for Apple GSS Framework [72]
  o hardening: add API guards [64]
  o RFC 9421 HTTP Message Signatures support [108]
 
 This release includes the following changes:
 
  o gssapi: add support for Apple GSS Framework [72]
  o hardening: add API guards [64]
  o RFC 9421 HTTP Message Signatures support [108]
+ o spnego: block NTLM fallback in SPNEGO negotiation [151]
  o TLS: drop support for TLS-SRP [71]
  o TLS: drop support for TLS-SRP [71]
+ o vquic: add option to use Apple fast UDP [137]
 
 This release includes the following bugfixes:
 
 
 This release includes the following bugfixes:
 
@@ -23,6 +25,7 @@ This release includes the following bugfixes:
  o build: enable thread-safe `getaddrinfo()` for OpenBSD [35]
  o cd2nroff: fix backslashes for 4-space indent lines [104]
  o cd2nroff: stricter checks for asterisks for italics [73]
  o build: enable thread-safe `getaddrinfo()` for OpenBSD [35]
  o cd2nroff: fix backslashes for 4-space indent lines [104]
  o cd2nroff: stricter checks for asterisks for italics [73]
+ o cf-ngtcp2-cmn: de-duplicate `ngtcp2_conn_client_new()` call code [156]
  o cf-ngtcp2-cmn: initialize new callback ptr for ngtcp2 1.24.0+ [52]
  o cfilters: fix event-based connection shutdown [91]
  o cmake: dedupe expressions into local vars in `cmake_uninstall.in.cmake` [9]
  o cf-ngtcp2-cmn: initialize new callback ptr for ngtcp2 1.24.0+ [52]
  o cfilters: fix event-based connection shutdown [91]
  o cmake: dedupe expressions into local vars in `cmake_uninstall.in.cmake` [9]
@@ -38,19 +41,25 @@ This release includes the following bugfixes:
  o configure: remove double check for GnuTLS [21]
  o configure: set ldap lib to no by default for non-finds [18]
  o conncache: apply multi limits to transfers using a shared pool [41]
  o configure: remove double check for GnuTLS [21]
  o configure: set ldap lib to no by default for non-finds [18]
  o conncache: apply multi limits to transfers using a shared pool [41]
+ o conncache: conn upkeep/alive: move and enhance [152]
  o conncache: connection alive checks intervals [20]
  o connect: connection close tweaks [112]
  o content_encoding: give a clear error on multi-member gzip [46]
  o CREDENTIALS.md: remove comment about empty user/pass [50]
  o ctype: exclude control bytes from ISPRINT and ISGRAPH [119]
  o conncache: connection alive checks intervals [20]
  o connect: connection close tweaks [112]
  o content_encoding: give a clear error on multi-member gzip [46]
  o CREDENTIALS.md: remove comment about empty user/pass [50]
  o ctype: exclude control bytes from ISPRINT and ISGRAPH [119]
+ o curl_gssapi: document/update feature availability [145]
  o curl_ws_meta.md: polish and better vocabulary [19]
  o CURLOPT_HEADERFUNCTION.md: document folded header unfolding [53]
  o CURLOPT_SSH_*_KEYFILE: used for setting up, then no more [48]
  o CURLOPT_UNRESTRICTED_AUTH.md: 'Authorization', not 'Authentication' [74]
  o CURLSHOPT_(UN)SHARE.md: do not modify shares while in use [44]
  o curl_ws_meta.md: polish and better vocabulary [19]
  o CURLOPT_HEADERFUNCTION.md: document folded header unfolding [53]
  o CURLOPT_SSH_*_KEYFILE: used for setting up, then no more [48]
  o CURLOPT_UNRESTRICTED_AUTH.md: 'Authorization', not 'Authentication' [74]
  o CURLSHOPT_(UN)SHARE.md: do not modify shares while in use [44]
+ o dnsd: fix bounds check in `read_https_alpn_part()` [143]
+ o docs/INTERNALS.md -> docs/DEPENDENCIES.md [127]
  o FTP: fix TLS session reuse on the data connection [80]
  o ftp: reject control bytes in ACCT and alternative-to-user [26]
  o gopher: reject CR and LF in the selector [1]
  o FTP: fix TLS session reuse on the data connection [80]
  o ftp: reject control bytes in ACCT and alternative-to-user [26]
  o gopher: reject CR and LF in the selector [1]
+ o h2: bootstrap max streams from multi handle if in use [132]
+ o HISTORY: add when c-ares support was introduced (2004)
  o hostip: only cache negative resolves for authoritative answers [16]
  o http: avoid length underflow in Curl_compareheader [78]
  o http: fix non-tunneling proxy hostname use [116]
  o hostip: only cache negative resolves for authoritative answers [16]
  o http: avoid length underflow in Curl_compareheader [78]
  o http: fix non-tunneling proxy hostname use [116]
@@ -60,8 +69,10 @@ This release includes the following bugfixes:
  o idn: restore `MultiByteToWideChar()` `MB_ERR_INVALID_CHARS` flag [103]
  o INSTALL.md: add building-from-source overview section [29]
  o INTERNALS.md: require quiche 0.20.0+ [101]
  o idn: restore `MultiByteToWideChar()` `MB_ERR_INVALID_CHARS` flag [103]
  o INSTALL.md: add building-from-source overview section [29]
  o INTERNALS.md: require quiche 0.20.0+ [101]
+ o ldap: support empty username and password [106]
  o ldap: support insecure mode for Windows native LDAP [3]
  o lib1587: fix gcc `-Wconversion` with LibreSSL on Windows, test in CI [6]
  o ldap: support insecure mode for Windows native LDAP [3]
  o lib1587: fix gcc `-Wconversion` with LibreSSL on Windows, test in CI [6]
+ o lib2405: adjust for non-threaded builds [149]
  o lib: add "Curl_" prefix to two global functions [84]
  o lib: add multi_wakeup_internal [86]
  o lib: fix 'ns' -> 'us' in trace messages [57]
  o lib: add "Curl_" prefix to two global functions [84]
  o lib: add multi_wakeup_internal [86]
  o lib: fix 'ns' -> 'us' in trace messages [57]
@@ -81,30 +92,42 @@ This release includes the following bugfixes:
  o openssl: drop unused pre-OpenSSL3 `ctx_option_t` typedef [8]
  o openssl: prefer modern API flavors for `EVP_MD_CTX` new/free [47]
  o openssl: replace stray legacy API variant with `EVP_DigestInit_ex()` [27]
  o openssl: drop unused pre-OpenSSL3 `ctx_option_t` typedef [8]
  o openssl: prefer modern API flavors for `EVP_MD_CTX` new/free [47]
  o openssl: replace stray legacy API variant with `EVP_DigestInit_ex()` [27]
+ o pytest: update two H3 tests for nghttp3 1.18.0+ [158]
  o quiche: set the max field section size [100]
  o runtests: allow comments in `setenv` section, merge sections in test433 [89]
  o runtests: fix `mode="warn"` tests passing unconditionally, fix test 1752 [66]
  o runtests: flush cached test parts when (re)loading a file [95]
  o runtests: restore `-k` option and actively process as no-op [32]
  o sasl: fix zero-length response encoding [36]
  o quiche: set the max field section size [100]
  o runtests: allow comments in `setenv` section, merge sections in test433 [89]
  o runtests: fix `mode="warn"` tests passing unconditionally, fix test 1752 [66]
  o runtests: flush cached test parts when (re)loading a file [95]
  o runtests: restore `-k` option and actively process as no-op [32]
  o sasl: fix zero-length response encoding [36]
+ o schannel: fix error check logic in `get_client_cert()` file reader [144]
  o schannel: shut off experimental TLS 1.3 support for Win 10 [25]
  o schannel: shut off experimental TLS 1.3 support for Win 10 [25]
+ o scorecard: fix `max_upload` init value in `ul_parallel()` [142]
+ o scripts/badwords.txt: do not recommend using 'will' in rewrites [141]
  o scripts: replace/extend `--` with `--end-of-options` in git commands [128]
  o scripts: use end-of-options marker in `cd`, `mkdir`, `mv`, `sha256sum` commands [34]
  o setopt: error for CURLOPT_SHARE when easy handle is used [68]
  o setopt: return OK earlier for the deprecated h2 dep options [77]
  o smtp: reject CR and LF in the envelope address [37]
  o spacecheck: cap number of lines per file [111]
  o scripts: replace/extend `--` with `--end-of-options` in git commands [128]
  o scripts: use end-of-options marker in `cd`, `mkdir`, `mv`, `sha256sum` commands [34]
  o setopt: error for CURLOPT_SHARE when easy handle is used [68]
  o setopt: return OK earlier for the deprecated h2 dep options [77]
  o smtp: reject CR and LF in the envelope address [37]
  o spacecheck: cap number of lines per file [111]
+ o src: safely clear certain buffers [125]
  o ssls: fix potential memory leak on import [96]
  o sws: allow connection-monitor to log all disconnects [2]
  o ssls: fix potential memory leak on import [96]
  o sws: allow connection-monitor to log all disconnects [2]
+ o sws: log the exact closing reason better, to help debugging tests [85]
  o terminal: Enhance terminal size detection for multiple outputs [115]
  o test 1560: test RFC4291 style IPv6 IPv4-mapped addresses [40]
  o test1560: allow to build and run without LDAP support [109]
  o test798: force IPv4 to avoid cross-runner port aliasing [97]
  o test: adjust test_06_13 for 0100::/64 being blackholed [13]
  o terminal: Enhance terminal size detection for multiple outputs [115]
  o test 1560: test RFC4291 style IPv6 IPv4-mapped addresses [40]
  o test1560: allow to build and run without LDAP support [109]
  o test798: force IPv4 to avoid cross-runner port aliasing [97]
  o test: adjust test_06_13 for 0100::/64 being blackholed [13]
+ o tests: address mutable class vars and naive datetime in Python code
+ o tests: change whitespace and comments in Python test code
  o tests: fix the FTP check for unexpected RST [117]
  o tests: fix type promotion on 32-bit arches in http test code [88]
  o tests: fix the FTP check for unexpected RST [117]
  o tests: fix type promotion on 32-bit arches in http test code [88]
+ o tests: improve exception handling in Python test code
  o tests: remove test1701 [58]
  o tests: remove test1701 [58]
+ o tests: simplify by removing unneeded Python code
  o tests: skip test 311 for wolfSSL 5.9.2 [63]
  o tests: skip test 311 for wolfSSL 5.9.2 [63]
+ o tests: target Python 3.8 as the minimum Python version
+ o tests: use simpler constructions in Python code
  o thrdpool: retry failed thread starts while items wait [62]
  o tidy-up: `TEXT()` vs `_TEXT()` vs `_T()` use (Windows) [102]
  o tidy-up: drop redundant includes [110]
  o thrdpool: retry failed thread starts while items wait [62]
  o tidy-up: `TEXT()` vs `_TEXT()` vs `_T()` use (Windows) [102]
  o tidy-up: drop redundant includes [110]
@@ -114,22 +137,29 @@ This release includes the following bugfixes:
  o tool: do not flush on out-null [38]
  o tool: fix memory use in parallel mode [59]
  o tool: init progress bar on demand [39]
  o tool: do not flush on out-null [38]
  o tool: fix memory use in parallel mode [59]
  o tool: init progress bar on demand [39]
+ o tool: remove duplicate setopts [94]
  o tool_cb_hdr: de-duplicate filename setter [24]
  o tool_cb_prg: avoid integer overflows [93]
  o tool_doswin: add stdin relay auth [130]
  o tool_operate: remove call to abort() [23]
  o tool_xattr: add support for Windows alternate data stream [129]
  o tool_cb_hdr: de-duplicate filename setter [24]
  o tool_cb_prg: avoid integer overflows [93]
  o tool_doswin: add stdin relay auth [130]
  o tool_operate: remove call to abort() [23]
  o tool_xattr: add support for Windows alternate data stream [129]
+ o typecheck-gcc: allow passing `char[]` as callback data [153]
  o uint-spbset: reused empty chunks [67]
  o unit3214: fix to pass on systems with >=128-bit pointers [107]
  o url: reject control codes in credentials set via CURLOPT [70]
  o urlapi: allow URLs to not have userauth (hostname) [92]
  o uint-spbset: reused empty chunks [67]
  o unit3214: fix to pass on systems with >=128-bit pointers [107]
  o url: reject control codes in credentials set via CURLOPT [70]
  o urlapi: allow URLs to not have userauth (hostname) [92]
+ o urlapi: clear password buffer on error path [121]
  o urlapi: do not keep an internal port string [31]
  o urlapi: do not keep an internal port string [31]
+ o urlapi: improved return codes [148]
  o urlapi: preserve empty markers in relative URLs [61]
  o vms: fix symbol typo and missing closing quotes in `config_h.com` [124]
  o vquic: add Curl_ prefix to some global functions [76]
  o vquic: initialize new callback slot for nghttp3 v1.18.0+ [87]
  o urlapi: preserve empty markers in relative URLs [61]
  o vms: fix symbol typo and missing closing quotes in `config_h.com` [124]
  o vquic: add Curl_ prefix to some global functions [76]
  o vquic: initialize new callback slot for nghttp3 v1.18.0+ [87]
+ o vquic: silence `-Wmissing-field-initializers` for nghttp3/ngtcp2 callback tables [159]
+ o vquic: use ngtcp2 v1.25.0 new close2 callback [154]
  o vssh: keyfile use cleanups [83]
  o VULN-DISCLOSURE-POLICY.md: issues that should be found by tests are LOW [5]
  o vssh: keyfile use cleanups [83]
  o VULN-DISCLOSURE-POLICY.md: issues that should be found by tests are LOW [5]
+ o websocket: pause writing and meta data fix [135]
  o wolfssl: fix build for wolfssl without bio chain support [75]
  o ws: pause/unpause write handling [55]
 
  o wolfssl: fix build for wolfssl without bio chain support [75]
  o ws: pause/unpause write handling [55]
 
@@ -154,16 +184,18 @@ advice from friends like these:
 
   11soda11, AlanKingPL, Alb3e3, Alhuda Khan, Bartel Sielski,
   Bigtang on hackerone, Bill Mill, Bryan Henderson,
 
   11soda11, AlanKingPL, Alb3e3, Alhuda Khan, Bartel Sielski,
   Bigtang on hackerone, Bill Mill, Bryan Henderson,
-  Carlos Henrique Lima Melara, Christian Ullrich, Christoph Reiter,
-  Collin Funk, Dan Fandrich, Daniel Stenberg, dependabot[bot],
+  Carlos Henrique Lima Melara, CatboxParadox, Christian Ullrich,
+  Christoph Reiter, claudex on github, Collin Funk, Dan Fandrich,
+  Daniel Gustafsson, Daniel Stenberg, dependabot[bot],
   ed0d2b2ce19451f2 on github, Emmanuel Ugwu, Eunsoo Kim, firexinghe on github,
   Graham Campbell, Hendrik Hübner, HwangRock, itzTanos29, Joel Depooter,
   ed0d2b2ce19451f2 on github, Emmanuel Ugwu, Eunsoo Kim, firexinghe on github,
   Graham Campbell, Hendrik Hübner, HwangRock, itzTanos29, Joel Depooter,
-  Keng-Yu Lin, Laurent Sabourin, Memduh Çelik, Patrick Monnerat, Pavel Sobolev,
+  Johannes Schindelin, Keng-Yu Lin, kit-ty-kate on github, Laurent Sabourin,
+  Matthew John Cheetham, Memduh Çelik, Patrick Monnerat, Pavel Sobolev,
   pszemus on github, Ray Satiro, renovate[bot], RMMoreton on github,
   Roger Leigh, Ross Burton, Sameeh Jubran, Sam James, Samuel Dainard,
   Sergei Zimmerman, smaeljaish on hackerone, Stefan Eissing, stze on hackerone,
   pszemus on github, Ray Satiro, renovate[bot], RMMoreton on github,
   Roger Leigh, Ross Burton, Sameeh Jubran, Sam James, Samuel Dainard,
   Sergei Zimmerman, smaeljaish on hackerone, Stefan Eissing, stze on hackerone,
-  Viktor Szakats, xmoezzz on github
-  (44 contributors)
+  Viktor Szakats, xmoezzz on github, Yoshiro Yoneya
+  (51 contributors)
 
 References to bug reports and discussions on issues:
 
 
 References to bug reports and discussions on issues:
 
@@ -249,6 +281,7 @@ References to bug reports and discussions on issues:
  [82] = https://curl.se/bug/?i=22248
  [83] = https://curl.se/bug/?i=22243
  [84] = https://curl.se/bug/?i=22245
  [82] = https://curl.se/bug/?i=22248
  [83] = https://curl.se/bug/?i=22243
  [84] = https://curl.se/bug/?i=22245
+ [85] = https://curl.se/bug/?i=22431
  [86] = https://curl.se/bug/?i=22272
  [87] = https://curl.se/bug/?i=22399
  [88] = https://curl.se/bug/?i=22210
  [86] = https://curl.se/bug/?i=22272
  [87] = https://curl.se/bug/?i=22399
  [88] = https://curl.se/bug/?i=22210
@@ -257,6 +290,7 @@ References to bug reports and discussions on issues:
  [91] = https://curl.se/bug/?i=22282
  [92] = https://curl.se/bug/?i=22279
  [93] = https://curl.se/bug/?i=22316
  [91] = https://curl.se/bug/?i=22282
  [92] = https://curl.se/bug/?i=22279
  [93] = https://curl.se/bug/?i=22316
+ [94] = https://curl.se/bug/?i=22433
  [95] = https://curl.se/bug/?i=22319
  [96] = https://curl.se/bug/?i=22323
  [97] = https://curl.se/bug/?i=22318
  [95] = https://curl.se/bug/?i=22319
  [96] = https://curl.se/bug/?i=22323
  [97] = https://curl.se/bug/?i=22318
@@ -267,6 +301,7 @@ References to bug reports and discussions on issues:
  [103] = https://curl.se/bug/?i=22326
  [104] = https://curl.se/bug/?i=22393
  [105] = https://curl.se/bug/?i=22320
  [103] = https://curl.se/bug/?i=22326
  [104] = https://curl.se/bug/?i=22393
  [105] = https://curl.se/bug/?i=22320
+ [106] = https://curl.se/bug/?i=22162
  [107] = https://curl.se/bug/?i=22299
  [108] = https://curl.se/bug/?i=22386
  [109] = https://curl.se/bug/?i=22312
  [107] = https://curl.se/bug/?i=22299
  [108] = https://curl.se/bug/?i=22386
  [109] = https://curl.se/bug/?i=22312
@@ -280,10 +315,30 @@ References to bug reports and discussions on issues:
  [118] = https://curl.se/bug/?i=22330
  [119] = https://curl.se/bug/?i=22371
  [120] = https://curl.se/bug/?i=22380
  [118] = https://curl.se/bug/?i=22330
  [119] = https://curl.se/bug/?i=22371
  [120] = https://curl.se/bug/?i=22380
+ [121] = https://curl.se/bug/?i=21637
  [122] = https://curl.se/bug/?i=22377
  [123] = https://curl.se/bug/?i=22376
  [124] = https://curl.se/bug/?i=22375
  [122] = https://curl.se/bug/?i=22377
  [123] = https://curl.se/bug/?i=22376
  [124] = https://curl.se/bug/?i=22375
+ [125] = https://curl.se/bug/?i=21637
  [126] = https://curl.se/bug/?i=22363
  [126] = https://curl.se/bug/?i=22363
+ [127] = https://curl.se/bug/?i=22430
  [128] = https://curl.se/bug/?i=22369
  [129] = https://curl.se/bug/?i=22354
  [130] = https://curl.se/bug/?i=21467
  [128] = https://curl.se/bug/?i=22369
  [129] = https://curl.se/bug/?i=22354
  [130] = https://curl.se/bug/?i=21467
+ [132] = https://curl.se/bug/?i=22418
+ [135] = https://curl.se/bug/?i=22413
+ [137] = https://curl.se/bug/?i=22341
+ [141] = https://curl.se/bug/?i=22422
+ [142] = https://curl.se/bug/?i=22421
+ [143] = https://curl.se/bug/?i=22420
+ [144] = https://curl.se/bug/?i=22415
+ [145] = https://curl.se/bug/?i=22419
+ [148] = https://curl.se/bug/?i=22337
+ [149] = https://curl.se/bug/?i=22414
+ [151] = https://curl.se/bug/?i=21315
+ [152] = https://curl.se/bug/?i=21806
+ [153] = https://curl.se/bug/?i=22409
+ [154] = https://curl.se/bug/?i=22270
+ [156] = https://curl.se/bug/?i=22401
+ [158] = https://curl.se/bug/?i=22397
+ [159] = https://curl.se/bug/?i=22400