Tech News

curl 8.15.0 Released With 233 Bugfixes and 334 Commits – Update Now

The curl development team has announced the release of curl 8.15.0 on July 16, 2025, marking the 269th release of the popular command-line tool and libcurl library. 

This update brings 233 documented bugfixes and represents 334 commits from the development community, showcasing continued active maintenance of the critical networking tool used by millions of developers worldwide.

curl 8.15.0 represents a focused maintenance release following a shorter development cycle of 42 days, bringing the total project lifespan to 9,980 days. 

Key Takeaways
1. curl 8.15.0 is the 269th release featuring 233 bugfixes and 334 commits over a 42-day development cycle, focusing on stability improvements rather than new features.
2. Support for Secure Transport and BearSSL backends has been removed - developers must migrate to alternative TLS libraries like OpenSSL or wolfSSL.
3. This release contains zero security fixes, indicating strong security posture in previous versions, with upgrades recommended primarily for stability benefits.
4. 57 contributors participated including 29 newcomers, bringing total project contributors to 3,460 and demonstrating continued robust community engagement.

The release maintains the existing 269 command-line options without introducing new functionality, instead concentrating on stability improvements and bug resolution

The cumulative statistics demonstrate the project’s maturity, with 12,282 total bugfixes addressed throughout curl’s development history.

The release maintains backward compatibility with existing libcurl implementations, preserving all 96 public libcurl functions and 308 curl_easy_setopt() options. 

This approach ensures that developers can upgrade without breaking existing applications that rely on curl’s extensive API surface. 

The development team emphasized that this release cycle prioritized code quality and reliability over feature expansion, achieving an impressive rate of 5.5 bugfixes per day during the development period.

Security and Platform Changes

A significant technical change in curl 8.15.0 involves the removal of support for Secure Transport and BearSSL backends. 

This decision reflects the project’s strategic focus on maintaining the most widely-used and actively-supported TLS implementations. 

Developers using applications that specifically relied on these backends will need to migrate to alternative TLS libraries such as OpenSSL, wolfSSL, or other supported implementations.

Notably, this release contains zero security fixes, indicating that the previous curl versions have maintained strong security posture. 

The project’s total security fix count remains at 167, demonstrating the team’s commitment to proactive security maintenance. 

This clean security record for the current release suggests that existing curl deployments can upgrade primarily for stability improvements rather than urgent security patches.

The curl 8.15.0 release showcases robust community engagement with 57 contributors participating in the development cycle, including 29 new contributors joining the project. 

This influx of fresh talent brought the total contributor count to 3,460 individuals. 

Additionally, 37 authors contributed code changes, with 16 making their first contributions to the project, expanding the author base to 1,392 total contributors.

The release presentation was live-streamed on Twitch at 10:00 CEST (08:00 UTC) on July 16, 2025, allowing the community to engage directly with the development team and learn about the technical improvements. 

Developers and system administrators are encouraged to review the full changelog and consider upgrading to benefit from the extensive bugfix improvements included in this release.

Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now 

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago