Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-408

JLSEC-2026-408

JLSEC Published
Modified
Affected Packages
CURL_jll < 8.5.0+0
LibCURL_jll < 8.2.1+0
Aliases / Upstream
CVE-2023-28320

A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using alarm() and siglongjmp(). When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.

References