A CVE Dispute

Aug 31, 2026 06:13 PM - 1 hour ago 3

A fewer years years agone the curl task signed up and became a CNA. This intends that we are masters of and tin allocate our ain CVE identifiers. For immoderate information problems wrong our territory, it is we who decides if the rumor should get a CVE aliases not. No much bogus CVEs.

57 CVEs

During these years we person published fifty-seven abstracted security vulnerabilities pinch their associated CVE identifiers. Getting a CVE for an rumor is easy and really quickly done erstwhile you are a CNA. No hassle, nary clash and arsenic we are a mini and thin information squad it conscionable useful arsenic smoothly arsenic you could ask. Just an API telephone and we person caller number.

Being a CNA is debased maintenance, arsenic location really is thing other we request to do. We already had an established and proven process for receiving, managing and assessing vulnerability reports earlier we became a CNA since we are a responsible and well-run Open Source project. Becoming a CNA conscionable made the process easier arsenic we now don’t request to impact immoderate outsider astatine all.

Assess

For each study we activity difficult to first measure and determine if the rumor is really a vulnerability aliases a information problem astatine all.

If we deem that location is simply a information problem successful there, we past people it into LOW, MEDIUM, HIGH aliases CRITICAL. Since we don’t cognize really users usage curl aliases libcurl we cannot return that into relationship but alternatively observe and group a severity of the problem from a axenic curl constituent of view.

It’s a unsmooth denotation really we spot the problem but of people each personification that really are affected by the problem mightiness complaint it differently.

Lower than LOW

For a uncommon fewer issues we tin imagine that location could beryllium a minuscule consequence but because of the group of utmost requirements and convoluted steps to get there, we deem the consequence truthful mini that successful believe nary personification is likely to ever scope it. Internally we thin to telephone that an rumor pinch a severity level little than LOW. Issues we judge we service humanity amended by not issuing a CVE for. To debar the information creation erstwhile it seems unnecessary.

The costs of a CVE

libcurl is installed successful location astir thirty cardinal instances connected the globe. If we ideate that astatine slightest a sizeable information of those installs are managed by group who want to make judge they usage a unafraid version, it intends that each CVE we people trigger activities successful galore information teams each complete the world, starring to a important number of patches and consequent package updates.

Every CVE frankincense has this immense costs tied to it. A costs that does not onshore connected america and we don’t really spot aliases consciousness it, but a costs connected the ecosystem I judge we should not ignore. We should enactment responsibly. Never disregard existent problems of course, but besides to make judge we don’t ringing the siren for theoretical problems that will not trigger immoderate vulnerability.

The dispute

Our first ever CVE conflict since we became a CNA reached america connected February 10th, 2026 for a study submitted to america 2 months earlier. The newsman thinks we should person assigned their reported problem a CVE but we deliberation not. Now they want to unit the rumor to get a CVE anyway, by escalating the business to MITRE.

Yes, it makes you wonderment why it is that important to person this arsenic a CVE, but I will debar speculations for now.

I replied to MITRE explaining that we considered and debated the rumor and we stay happy pinch our erstwhile decision. I linked them the original study and chat to show them.

Hostname pinch a starring dot

The rumor is rather method (of course) but is based connected a bug successful curl’s usability that checks if the utilized hostname matches a wildcard provided successful a certificate.

First: the personification must usage a hostname successful a URL pinch a leading dot, for illustration https://.example.com/

This sanction is not imaginable to usage pinch DNS (it is an forbidden sanction there), but you tin supply an IP reside for it successful your /etc/hosts record aliases similar, but still this information is already making this rumor really niche.

Why would a personification ever do this? Well, location could beryllium a redirect to specified a big sanction from a malicious server if the exertion allows redirects but getting the reside for the big is still a situation and mostly requires a section attacker coming adhd that.

Then: if curl tin find an reside for the forbidden DNS hostname, the tract curl connects to, besides needs to person a wildcard certificate for the sanction *.example.com wherever the tail of the wildcard needs to lucifer the sanction successful the URL.

If curl was built to usage an OpenSSL spirit aliases Schannel for TLS (remember that curl supports galore different TLS backends), it past calls the Curl_cert_hostcheck() usability to cheque if the wildcard covers the utilized hostname.

This usability had a bug. The supra mention operation past erroneously would return TRUE. A match. When successful reality it is not a lucifer according to the spec.

We fixed this problem connected December 8, 2025, and we added portion tests for precisely this script to make judge that the problem doesn’t travel back. For each information issues astatine respective beneath HIGH, we hole them asap truthful that was conscionable our normal procedure. We past continued to talk if this was worthy of a CVE aliases not.

Lower than LOW

It should beryllium extremely rare that anyone uses a dot prefixed name, unless you are successful an soul and controlled situation wherever you usage thing other than DNS for resolving.

It is not imaginable to instrumentality an exertion to usage a dot prefixed arbitrary sanction arsenic it will neglect to resolve.

The explicitly set, weirdly dot prefixed name, past needs to link to a big that has a wildcard group for that aforesaid sanction and an attacker negociate to tally this impostor big and tin now service the exertion malicious information because curl did not decently cull the relationship because of the wildcard mismatch.

A bid of highly improbable conditions that each request to beryllium fulfilled for this to go a vulnerability. A little than LOW situation. Too unlikely; nary CVE.

Again successful May

On May 28, we were again contacted by MITRE in the aforesaid case, asking again for our rationale for not giving this rumor a CVE. We responded pinch virtually the aforesaid wording arsenic earlier and linking again to the aforesaid original Hackerone rumor and chat thread. It’s each nationalist accusation really.

Again successful June

On June 15, we were again contacted by MITRE asking for the reasoning down our determination to not springiness a CVE for this issue.

We replied pinch akin wording again. Linking to the aforesaid issue, again.

This seems for illustration a great system.

Verdict

On June 24 we yet sewage the verdict. It is not considered a information vulnerability.

Hello Yuhao,

Thank you for your information successful the CVE conflict process regarding the reported rumor affecting curl done 8.17.0.

The MITRE TL-Root has completed its reappraisal of the accusation provided by each parties involved,
including the materials submitted by you and the consequence from the responsible CNA. Based connected this
review, the MITRE TL-Root has wished that a CVE ID will not beryllium assigned for the reported issue.

CNA Determination (Summary):

"This is simply a bug, now fixed successful the maestro branch. It is not considered a information vulnerability because of really it requires a section attacker pinch privileges coming to make it so."

After evaluating the disposable grounds and the CNA’s assessment, the MITRE TL-Root agrees pinch this determination and considers the matter resolved. As the adjudicating authority successful this conflict process, the determination of the MITRE TL-Root represents the last determination for this case.

We admit your engagement pinch the CVE Program and your efforts to responsibly study and coordinate information issues.

Respectfully,

MITRE TL-Root

More