# curl 8.21.0 - Product: curl (https://whatsnew.fyi/product/curl) - Vendor: curl - Date: 2026-06-24 - Version: 8.21.0 - Original notes: https://curl.se/ch/8.21.0.html - Permalink: https://whatsnew.fyi/product/curl/releases/8.21.0 - Labels: Platforms: Desktop What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — curl: named globs in output filename for upload glob references - **added** — HTTP/3: add proxy CONNECT and MASQUE CONNECT-UDP support (ngtcp2 QUIC) - **added** — libssh: add support for SHA256 host public keys - **changed** — http2: remove stream dependency tracking - **removed** — lib: drop support for CURLAUTH_DIGEST_IE - **fixed** — cfilters: fix busy loop on blocked transfers - **fixed** — chunked: reject invalid bytes in trailer - **fixed** — cf-socket: set scope_id for IPv6 link-local addresses - **fixed** — cookie: check __Secure- and __Host- case sensitively when read from file - **fixed** — cookie: compare path case sensitively - **fixed** — cookie: reject control octets in file-loaded cookies - **fixed** — curl_ntlm_core: fix nettle 4+ builds in certain MultiSSL combos - **fixed** — digest: flush proxy state on proxy or credential change - **fixed** — doh: cap the maximum TTL to 24 hours - **fixed** — event: fix wakeup consumption - **fixed** — ftp: avoid accessing EPSV response one byte past the NULL - **fixed** — gsasl: fix potential double free - **fixed** — http-proxy: verify CONNECT response headers - **fixed** — http: reject spurious CR bytes in headers - **fixed** — AmigaOS: fix build fallouts, re-add to CI curl / Docs / Releases / Changes in 8.21.0 Related: Daily Snapshots Source repo Release log Pending Release 🠰 8.20.0 all changes pending release #### Changes in 8.21.0 - June 24 2026 8.21.0 8.21.0 Changes: - curl: named globs in output filename for upload glob references - HTTP/3: add proxy CONNECT and MASQUE CONNECT-UDP support (ngtcp2 QUIC) - http2: remove stream dependency tracking - lib: drop support for CURLAUTH_DIGEST_IE - libssh: add support for SHA256 host public keys - tool_urlglob: add named globs Bugfixes: - _ENVIRONMENT.md. Windows does case insensitive env variables - _URL.md: remove the zone-id mention - AmigaOS: curl_setup.h avoid explicit_bzero with clib2 - AmigaOS: fix build fallouts, re-add to CI - asyn-thrdd: add IPv6 guards - asyn-thrdd: fix result processing without wakeup socketpair - autotools: mbedtls detection fixes - BINDINGS: Update Hollywood link - BUFQ.md: re-sync with source code - build: enable `-Wlogical-op` picky warning for GCC 4.4+ - build: omit zlib pkg-config reference for Android - cf-h2-prox: fix peer leak - cf-h2-proxy: drop interim responses - cf-https-connect: do not engage on proxy origin - cf-ip-happy.c: minor comment typo - cf-ip-happy: update documentation - cf-socket: make Curl_addr2string static - cf-socket: set scope_id for IPv6 link-local addresses - cf-socket: store errno from do_connect in ctx->error - cfilters: fix busy loop on blocked transfers - chunked: reject invalid bytes in trailer - CIPHERS.md: fix the example that uses only TLS 1.3 - cmake/FindGSS: drop "MIT Unknown" version value, related tidy ups - cmake/FindGSS: drop CMake <3.16 compatibility logic - cmake/FindGSS: fix comment, adjust custom flavor property name - cmake/FindGSS: prioritize MIT over GNU in pkg-config detection - cmake: auto-select static nghttp2/nghttp3/ngtcp2 Config - cmake: export/forward `NGTCP2_CRYPTO_BACKEND` - cmake: fix three issues generating lib options in config files - cmake: fix zstd CMake config name - cmake: opt in `MSVC_VERSION` 1951 to picky warnings - cmake: quote `COMPONENTS` string in `curl-config.in.cmake` - cmake: simplify `LINK_ONLY` imported target extraction - config2setopts: use default protocol properly - connect: remove deref of freed pointer in trace call - content_encoding: fix limit failure message - content_encoding: fix non-last chunked rejection - content_encoding: timeout during slow decoding - cookie: check __Secure- and __Host- case sensitively when read from file - cookie: compare path case sensitively - cookie: reject control octets in file-loaded cookies - cookie: simplify strstore(), remove outdated comment - cookie: tailmatch the domains for secure override - cookie: trim trailing dots when checking PSL - creds: add sasl service name - creds: create with empty user+pass - creds: mask OAuth bearer token in trace logs - creds: remove two unused functions - curl_easy_pause.md: rephrase the stream cache when pause clause - curl_easy_setopt.md: change options when no transfer runs - curl_formdata: fix to pass long where missing, document `CURLFORM_NAMELENGTH` - curl_multi_assign.md: clarify lifetime - curl_ntlm_core: fix nettle 4+ builds in certain MultiSSL combos - curl_ntlm_core: propagate DES `CryptEncrypt()` error - curl_sha512_256: fix result code on error - CURLINFO_CONTENT_LENGTH_UPLOAD_T.md: expand - CURLMOPT_SOCKETFUNCTION.md: this sends *all* file descriptors - CURLOPT_CHUNK_BGN_FUNCTION: target is there for symlinks only - CURLOPT_DISALLOW_USERNAME_IN_URL: is for CURLOPT_URL only - CURLOPT_DOH_URL.md: does not inherit proxy options - CURLOPT_ECH.md: simplify the description language - CURLOPT_HAPROXYPROTOCOL.md: only sent for newly setup connections - CURLOPT_MAXFILESIZE: clarify this also works for on-going transfers - CURLOPT_PINNEDPUBLICKEY.md: does not apply for other origins - CURLOPT_PORT.md: use stronger language - CURLOPT_SHARE: warn about early remove - CURLOPT_SSH_HOSTKEYFUNCTION.md: for new connections only - CURLOPT_WRITEFUNCTION.md: menti _[Truncated at 4000 characters — full notes: https://curl.se/ch/8.21.0.html]_