This update for curl fixes the following issues:
CVE-2025-9086: Fixed Out of bounds read for cookie path (bsc#1249191)
CVE-2025-10148: Predictable WebSocket mask (bsc#1249348)
Fix the --ftp-pasv option in curl v8.14.1 [bsc#1246197]
tool_operate: fix return code when --retry is used but not triggered [bsc#1249367]
Updated to 8.14.1: [jsc#PED-13055, jsc#PED-13056]
Sync spec file with SLE codestreams: [jsc#PED-13055, jsc#PED-13056]
Update to 8.14.0:
Changes:
Bugfixes:
default_bits from .prm filesUSE_OPENSSL_QUIC=ONCOMPILE_OPTIONS over CMAKE_C_FLAGS for custom C optionsCURL_LTO behavior for multi-config generators-Wnull-dereference, add assertUpdate to 8.13.0:
Changes:
Bugfixes:
gotos into other scopeAuthorizedKeysFile2 cutoff versionE* constants with TFTP_Update to 8.12.1:
Update to 8.12.0:
Changes:
Bugfixes:
HAVE_KEYLOG_CALLBACK before use