]> git.ipfire.org Git - thirdparty/curl.git/commitdiff
RELEASE-NOTES: synced master
authorDaniel Stenberg <daniel@haxx.se>
Thu, 30 Jul 2026 07:12:28 +0000 (09:12 +0200)
committerDaniel Stenberg <daniel@haxx.se>
Thu, 30 Jul 2026 07:12:28 +0000 (09:12 +0200)
RELEASE-NOTES

index b750535fa1d20c173732006a6294a1b17b54eeee..8c709a35d39a2c8de224cb224e7b3b8f54ad5cdb 100644 (file)
@@ -4,15 +4,17 @@ curl and libcurl 8.22.0
  Command line options:         278
  curl_easy_setopt() options:   312
  Public functions in libcurl:  100
- Authors:                      1500
- Contributors:                 3753
+ Authors:                      1502
+ Contributors:                 3756
 
 This release includes the following changes:
 
  o gssapi: add support for Apple GSS Framework [72]
  o hardening: add API guards [64]
  o RFC 9421 HTTP Message Signatures support [108]
+ o spnego: block NTLM fallback in SPNEGO negotiation [151]
  o TLS: drop support for TLS-SRP [71]
+ o vquic: add option to use Apple fast UDP [137]
 
 This release includes the following bugfixes:
 
@@ -23,6 +25,7 @@ This release includes the following bugfixes:
  o build: enable thread-safe `getaddrinfo()` for OpenBSD [35]
  o cd2nroff: fix backslashes for 4-space indent lines [104]
  o cd2nroff: stricter checks for asterisks for italics [73]
+ o cf-ngtcp2-cmn: de-duplicate `ngtcp2_conn_client_new()` call code [156]
  o cf-ngtcp2-cmn: initialize new callback ptr for ngtcp2 1.24.0+ [52]
  o cfilters: fix event-based connection shutdown [91]
  o cmake: dedupe expressions into local vars in `cmake_uninstall.in.cmake` [9]
@@ -38,19 +41,25 @@ This release includes the following bugfixes:
  o configure: remove double check for GnuTLS [21]
  o configure: set ldap lib to no by default for non-finds [18]
  o conncache: apply multi limits to transfers using a shared pool [41]
+ o conncache: conn upkeep/alive: move and enhance [152]
  o conncache: connection alive checks intervals [20]
  o connect: connection close tweaks [112]
  o content_encoding: give a clear error on multi-member gzip [46]
  o CREDENTIALS.md: remove comment about empty user/pass [50]
  o ctype: exclude control bytes from ISPRINT and ISGRAPH [119]
+ o curl_gssapi: document/update feature availability [145]
  o curl_ws_meta.md: polish and better vocabulary [19]
  o CURLOPT_HEADERFUNCTION.md: document folded header unfolding [53]
  o CURLOPT_SSH_*_KEYFILE: used for setting up, then no more [48]
  o CURLOPT_UNRESTRICTED_AUTH.md: 'Authorization', not 'Authentication' [74]
  o CURLSHOPT_(UN)SHARE.md: do not modify shares while in use [44]
+ o dnsd: fix bounds check in `read_https_alpn_part()` [143]
+ o docs/INTERNALS.md -> docs/DEPENDENCIES.md [127]
  o FTP: fix TLS session reuse on the data connection [80]
  o ftp: reject control bytes in ACCT and alternative-to-user [26]
  o gopher: reject CR and LF in the selector [1]
+ o h2: bootstrap max streams from multi handle if in use [132]
+ o HISTORY: add when c-ares support was introduced (2004)
  o hostip: only cache negative resolves for authoritative answers [16]
  o http: avoid length underflow in Curl_compareheader [78]
  o http: fix non-tunneling proxy hostname use [116]
@@ -60,8 +69,10 @@ This release includes the following bugfixes:
  o idn: restore `MultiByteToWideChar()` `MB_ERR_INVALID_CHARS` flag [103]
  o INSTALL.md: add building-from-source overview section [29]
  o INTERNALS.md: require quiche 0.20.0+ [101]
+ o ldap: support empty username and password [106]
  o ldap: support insecure mode for Windows native LDAP [3]
  o lib1587: fix gcc `-Wconversion` with LibreSSL on Windows, test in CI [6]
+ o lib2405: adjust for non-threaded builds [149]
  o lib: add "Curl_" prefix to two global functions [84]
  o lib: add multi_wakeup_internal [86]
  o lib: fix 'ns' -> 'us' in trace messages [57]
@@ -81,30 +92,42 @@ This release includes the following bugfixes:
  o openssl: drop unused pre-OpenSSL3 `ctx_option_t` typedef [8]
  o openssl: prefer modern API flavors for `EVP_MD_CTX` new/free [47]
  o openssl: replace stray legacy API variant with `EVP_DigestInit_ex()` [27]
+ o pytest: update two H3 tests for nghttp3 1.18.0+ [158]
  o quiche: set the max field section size [100]
  o runtests: allow comments in `setenv` section, merge sections in test433 [89]
  o runtests: fix `mode="warn"` tests passing unconditionally, fix test 1752 [66]
  o runtests: flush cached test parts when (re)loading a file [95]
  o runtests: restore `-k` option and actively process as no-op [32]
  o sasl: fix zero-length response encoding [36]
+ o schannel: fix error check logic in `get_client_cert()` file reader [144]
  o schannel: shut off experimental TLS 1.3 support for Win 10 [25]
+ o scorecard: fix `max_upload` init value in `ul_parallel()` [142]
+ o scripts/badwords.txt: do not recommend using 'will' in rewrites [141]
  o scripts: replace/extend `--` with `--end-of-options` in git commands [128]
  o scripts: use end-of-options marker in `cd`, `mkdir`, `mv`, `sha256sum` commands [34]
  o setopt: error for CURLOPT_SHARE when easy handle is used [68]
  o setopt: return OK earlier for the deprecated h2 dep options [77]
  o smtp: reject CR and LF in the envelope address [37]
  o spacecheck: cap number of lines per file [111]
+ o src: safely clear certain buffers [125]
  o ssls: fix potential memory leak on import [96]
  o sws: allow connection-monitor to log all disconnects [2]
+ o sws: log the exact closing reason better, to help debugging tests [85]
  o terminal: Enhance terminal size detection for multiple outputs [115]
  o test 1560: test RFC4291 style IPv6 IPv4-mapped addresses [40]
  o test1560: allow to build and run without LDAP support [109]
  o test798: force IPv4 to avoid cross-runner port aliasing [97]
  o test: adjust test_06_13 for 0100::/64 being blackholed [13]
+ o tests: address mutable class vars and naive datetime in Python code
+ o tests: change whitespace and comments in Python test code
  o tests: fix the FTP check for unexpected RST [117]
  o tests: fix type promotion on 32-bit arches in http test code [88]
+ o tests: improve exception handling in Python test code
  o tests: remove test1701 [58]
+ o tests: simplify by removing unneeded Python code
  o tests: skip test 311 for wolfSSL 5.9.2 [63]
+ o tests: target Python 3.8 as the minimum Python version
+ o tests: use simpler constructions in Python code
  o thrdpool: retry failed thread starts while items wait [62]
  o tidy-up: `TEXT()` vs `_TEXT()` vs `_T()` use (Windows) [102]
  o tidy-up: drop redundant includes [110]
@@ -114,22 +137,29 @@ This release includes the following bugfixes:
  o tool: do not flush on out-null [38]
  o tool: fix memory use in parallel mode [59]
  o tool: init progress bar on demand [39]
+ o tool: remove duplicate setopts [94]
  o tool_cb_hdr: de-duplicate filename setter [24]
  o tool_cb_prg: avoid integer overflows [93]
  o tool_doswin: add stdin relay auth [130]
  o tool_operate: remove call to abort() [23]
  o tool_xattr: add support for Windows alternate data stream [129]
+ o typecheck-gcc: allow passing `char[]` as callback data [153]
  o uint-spbset: reused empty chunks [67]
  o unit3214: fix to pass on systems with >=128-bit pointers [107]
  o url: reject control codes in credentials set via CURLOPT [70]
  o urlapi: allow URLs to not have userauth (hostname) [92]
+ o urlapi: clear password buffer on error path [121]
  o urlapi: do not keep an internal port string [31]
+ o urlapi: improved return codes [148]
  o urlapi: preserve empty markers in relative URLs [61]
  o vms: fix symbol typo and missing closing quotes in `config_h.com` [124]
  o vquic: add Curl_ prefix to some global functions [76]
  o vquic: initialize new callback slot for nghttp3 v1.18.0+ [87]
+ o vquic: silence `-Wmissing-field-initializers` for nghttp3/ngtcp2 callback tables [159]
+ o vquic: use ngtcp2 v1.25.0 new close2 callback [154]
  o vssh: keyfile use cleanups [83]
  o VULN-DISCLOSURE-POLICY.md: issues that should be found by tests are LOW [5]
+ o websocket: pause writing and meta data fix [135]
  o wolfssl: fix build for wolfssl without bio chain support [75]
  o ws: pause/unpause write handling [55]
 
@@ -154,16 +184,18 @@ advice from friends like these:
 
   11soda11, AlanKingPL, Alb3e3, Alhuda Khan, Bartel Sielski,
   Bigtang on hackerone, Bill Mill, Bryan Henderson,
-  Carlos Henrique Lima Melara, Christian Ullrich, Christoph Reiter,
-  Collin Funk, Dan Fandrich, Daniel Stenberg, dependabot[bot],
+  Carlos Henrique Lima Melara, CatboxParadox, Christian Ullrich,
+  Christoph Reiter, claudex on github, Collin Funk, Dan Fandrich,
+  Daniel Gustafsson, Daniel Stenberg, dependabot[bot],
   ed0d2b2ce19451f2 on github, Emmanuel Ugwu, Eunsoo Kim, firexinghe on github,
   Graham Campbell, Hendrik Hübner, HwangRock, itzTanos29, Joel Depooter,
-  Keng-Yu Lin, Laurent Sabourin, Memduh Çelik, Patrick Monnerat, Pavel Sobolev,
+  Johannes Schindelin, Keng-Yu Lin, kit-ty-kate on github, Laurent Sabourin,
+  Matthew John Cheetham, Memduh Çelik, Patrick Monnerat, Pavel Sobolev,
   pszemus on github, Ray Satiro, renovate[bot], RMMoreton on github,
   Roger Leigh, Ross Burton, Sameeh Jubran, Sam James, Samuel Dainard,
   Sergei Zimmerman, smaeljaish on hackerone, Stefan Eissing, stze on hackerone,
-  Viktor Szakats, xmoezzz on github
-  (44 contributors)
+  Viktor Szakats, xmoezzz on github, Yoshiro Yoneya
+  (51 contributors)
 
 References to bug reports and discussions on issues:
 
@@ -249,6 +281,7 @@ References to bug reports and discussions on issues:
  [82] = https://curl.se/bug/?i=22248
  [83] = https://curl.se/bug/?i=22243
  [84] = https://curl.se/bug/?i=22245
+ [85] = https://curl.se/bug/?i=22431
  [86] = https://curl.se/bug/?i=22272
  [87] = https://curl.se/bug/?i=22399
  [88] = https://curl.se/bug/?i=22210
@@ -257,6 +290,7 @@ References to bug reports and discussions on issues:
  [91] = https://curl.se/bug/?i=22282
  [92] = https://curl.se/bug/?i=22279
  [93] = https://curl.se/bug/?i=22316
+ [94] = https://curl.se/bug/?i=22433
  [95] = https://curl.se/bug/?i=22319
  [96] = https://curl.se/bug/?i=22323
  [97] = https://curl.se/bug/?i=22318
@@ -267,6 +301,7 @@ References to bug reports and discussions on issues:
  [103] = https://curl.se/bug/?i=22326
  [104] = https://curl.se/bug/?i=22393
  [105] = https://curl.se/bug/?i=22320
+ [106] = https://curl.se/bug/?i=22162
  [107] = https://curl.se/bug/?i=22299
  [108] = https://curl.se/bug/?i=22386
  [109] = https://curl.se/bug/?i=22312
@@ -280,10 +315,30 @@ References to bug reports and discussions on issues:
  [118] = https://curl.se/bug/?i=22330
  [119] = https://curl.se/bug/?i=22371
  [120] = https://curl.se/bug/?i=22380
+ [121] = https://curl.se/bug/?i=21637
  [122] = https://curl.se/bug/?i=22377
  [123] = https://curl.se/bug/?i=22376
  [124] = https://curl.se/bug/?i=22375
+ [125] = https://curl.se/bug/?i=21637
  [126] = https://curl.se/bug/?i=22363
+ [127] = https://curl.se/bug/?i=22430
  [128] = https://curl.se/bug/?i=22369
  [129] = https://curl.se/bug/?i=22354
  [130] = https://curl.se/bug/?i=21467
+ [132] = https://curl.se/bug/?i=22418
+ [135] = https://curl.se/bug/?i=22413
+ [137] = https://curl.se/bug/?i=22341
+ [141] = https://curl.se/bug/?i=22422
+ [142] = https://curl.se/bug/?i=22421
+ [143] = https://curl.se/bug/?i=22420
+ [144] = https://curl.se/bug/?i=22415
+ [145] = https://curl.se/bug/?i=22419
+ [148] = https://curl.se/bug/?i=22337
+ [149] = https://curl.se/bug/?i=22414
+ [151] = https://curl.se/bug/?i=21315
+ [152] = https://curl.se/bug/?i=21806
+ [153] = https://curl.se/bug/?i=22409
+ [154] = https://curl.se/bug/?i=22270
+ [156] = https://curl.se/bug/?i=22401
+ [158] = https://curl.se/bug/?i=22397
+ [159] = https://curl.se/bug/?i=22400