HTTP Message Signatures with #curl
https://daniel.haxx.se/blog/2026/07/27/http-message-signatures-with-curl/
218 posts
HTTP Message Signatures with #curl
https://daniel.haxx.se/blog/2026/07/27/http-message-signatures-with-curl/
Welcome Sameeh Jubran as #curl commit author 1500: https://github.com/curl/curl/pull/22386
Welcome AlanKingPL as #curl commit author 1499: https://github.com/curl/curl/pull/22276
No #curl CVEs at all during July because of bliss. Highly recommended.
Welcome Pavel Sobolev as #curl commit author 1498: https://github.com/curl/curl/pull/22363
Welcome Alb3e3 as #curl commit author 1497: https://github.com/curl/curl/pull/22298
Dear #network teachers, students and #hacker friends, I have a #browser based network simulator to enable learning #networking. Please have a look and tell me what do you think. Made for desktop or bigger screens.
https://howcomputer.works/netsim/ Everything is in the browser, and there is documentation.
The goal is to allow kids to start learning while their schools/systems are not big enough to be able to build lab networks. It has a small/minimal #curl implementation too. @bagder
glibc has this open bug to resolve link-local host names for AF_INET6 since 2012
https://sourceware.org/bugzilla/show_bug.cgi?id=14413
Now this causes problems to #curl, as it now does separate name resolves for IPv4 and IPv6 in order to start connecting once the first response is in. 😕
The current top story on the FT Magazine is pay-walled but features some mentions of #curl and yours truly... (the picture shows the start of it)
https://www.ft.com/content/cec8df9e-b43b-4cd1-8feb-c07e804e8d33
Welcome itzTanos29 as #curl commit author 1494: https://github.com/curl/curl/pull/22297
With the #curl #summerofbliss I get the chance to look at performance and memory use again. Opportunities otherwise stolen away be the clankers and their minions.🙂↔️
Bliss in progress. #curl maintainer on a beach.
Questions are being raised.
https://github.com/curl/curl/discussions/22263#discussioncomment-17544243
The feature window for #curl 8.22.0 is OPEN
The #curl summer of bliss continues to be great and even greater. You realize the pressure possible 24/7 security reports exert when it is gone.
Recommended.
We do not accept #curl vulnerability reports over email. Not sent to my private email either. See https://curl.se/dev/vuln-disclosure.html
The mythos report for #curl 2026-05-06 made public:
https://gist.github.com/bagder/c9b83a19f30e82e41b11f6315465b17a
Is it time for another #curl graph? 70, 80 and 90 of all commits were done by this many authors, over time
Welcome Emmanuel Ugwu as #curl commit author 1493: https://github.com/curl/curl/pull/22231
On this day nine years ago, #curl was adopted into the oss-fuzz project.
Over this time it has found 200+ issues. Some false positives, but most of them true bugs that we fixed.
These days it rarely triggers and when it does, it is now often in 3rd party libs. We have recently helped report problems in both OpenLDAP and OpenSSL via our fuzzing reports.
Upgraded #curl graph:
The security reporters are passive aggressively not sending in new reports a day before the #curl summer of bliss starts.
Welcome Memduh Çelik as #curl commit author 1492: https://github.com/curl/curl/pull/22224
Welcome HwangRock as #curl commit author 1491: https://github.com/curl/curl/pull/22172
Guess how many more hackerone submissions will we receive for #curl before the bliss starts ? (starting count NOW)
The #curl summer of bliss is just two days out
https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/
A #curl mountain movie
https://daniel.haxx.se/blog/2026/06/26/a-curl-mountain-movie/