<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Libcurl in update is version 8.15.0, which is flagged with CVE-2025-14819 &#x2F; CVE-2025-14017, but the GUP uses version 8.19.0?]]></title><description><![CDATA[<p dir="auto">We reviewed a local Notepad++ 8.9.3 installation and found that updater\libcurl.dll is present, with Windows file metadata reporting version 8.15.0. This version is flagged by our vulnerability scanner in relation to CVE-2025-14819 / CVE-2025-14017 (libcurl versions before 8.18.0).</p>
<p dir="auto">However, our local static analysis of updater\GUP.exe (version 5.41) did not show a normal import or delay-load import of libcurl.dll. In addition, GUP.exe contains strings referencing libcurl 8.19.0 (for example CLIENT libcurl 8.19.0), which suggests that the updater may be using a statically linked or otherwise embedded libcurl, rather than the separate updater\libcurl.dll.</p>
<p dir="auto">Could you please confirm whether the bundled updater\libcurl.dll is actually used at runtime by Notepad++ / WinGUp? If it is not used, it may be worth removing or updating that DLL to avoid false positive vulnerability findings in security scans.</p>
<p dir="auto">This assessment is based on local static analysis only; we have not yet verified the runtime module loading behavior.</p>
<p dir="auto">Thanks.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27493/libcurl-in-update-is-version-8-15-0-which-is-flagged-with-cve-2025-14819-cve-2025-14017-but-the-gup-uses-version-8-19-0</link><generator>RSS for Node</generator><lastBuildDate>Thu, 16 Apr 2026 12:57:00 GMT</lastBuildDate><atom:link href="https://community.notepad-plus-plus.org/topic/27493.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 15 Apr 2026 09:23:22 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Libcurl in update is version 8.15.0, which is flagged with CVE-2025-14819 &#x2F; CVE-2025-14017, but the GUP uses version 8.19.0? on Wed, 15 Apr 2026 19:19:35 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/288">@xomx</a><br />
Thank you for pinging!<br />
<a href="https://github.com/notepad-plus-plus/notepad-plus-plus/commit/2c1abe0784543e78dbba0f259b0948cf3a08b8cb" rel="nofollow ugc">https://github.com/notepad-plus-plus/notepad-plus-plus/commit/2c1abe0784543e78dbba0f259b0948cf3a08b8cb</a></p>
]]></description><link>https://community.notepad-plus-plus.org/post/105250</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/105250</guid><dc:creator><![CDATA[donho]]></dc:creator><pubDate>Wed, 15 Apr 2026 19:19:35 GMT</pubDate></item><item><title><![CDATA[Reply to Libcurl in update is version 8.15.0, which is flagged with CVE-2025-14819 &#x2F; CVE-2025-14017, but the GUP uses version 8.19.0? on Wed, 15 Apr 2026 16:53:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38839">@Cheece777</a></p>
<p dir="auto">I pass the info to the N++ maintainer:<br />
<a href="https://github.com/notepad-plus-plus/notepad-plus-plus/commit/b34b5b13e82c2af0b47451642ea9680da0dffd24#commitcomment-182497025" rel="nofollow ugc">https://github.com/notepad-plus-plus/notepad-plus-plus/commit/b34b5b13e82c2af0b47451642ea9680da0dffd24#commitcomment-182497025</a></p>
]]></description><link>https://community.notepad-plus-plus.org/post/105249</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/105249</guid><dc:creator><![CDATA[xomx]]></dc:creator><pubDate>Wed, 15 Apr 2026 16:53:46 GMT</pubDate></item><item><title><![CDATA[Reply to Libcurl in update is version 8.15.0, which is flagged with CVE-2025-14819 &#x2F; CVE-2025-14017, but the GUP uses version 8.19.0? on Wed, 15 Apr 2026 12:32:51 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/288">@xomx</a> Thanks for the quick reply.</p>
<p dir="auto">Do you plan to remove the leftover updater\libcurl.dll in a future release? If so, we can document this as a false positive on our side.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/105248</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/105248</guid><dc:creator><![CDATA[Cheece777]]></dc:creator><pubDate>Wed, 15 Apr 2026 12:32:51 GMT</pubDate></item><item><title><![CDATA[Reply to Libcurl in update is version 8.15.0, which is flagged with CVE-2025-14819 &#x2F; CVE-2025-14017, but the GUP uses version 8.19.0? on Wed, 15 Apr 2026 12:17:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38839">@Cheece777</a> said in <a href="/post/105245">Libcurl in update is version 8.15.0, which is flagged with CVE-2025-14819 / CVE-2025-14017, but the GUP uses version 8.19.0?</a>:</p>
<blockquote>
<p dir="auto">found that updater\libcurl.dll is present, with Windows file metadata reporting version 8.15.0.</p>
</blockquote>
<p dir="auto">That is probably a remnant from a previous version.</p>
<blockquote>
<p dir="auto">our local static analysis of updater\GUP.exe (version 5.41) did not show a normal import or delay-load import of libcurl.dll. In addition, GUP.exe contains strings referencing libcurl 8.19.0 (for example CLIENT libcurl 8.19.0), which suggests that the updater may be using a statically linked or otherwise embedded libcurl, rather than the separate updater\libcurl.dll.</p>
</blockquote>
<p dir="auto">Yes, it’s now linked statically.</p>
<p dir="auto">More info:</p>
<ul>
<li><a href="https://github.com/notepad-plus-plus/wingup/commit/c172e6874551d02814e1474cc6662fd4c9bd8eb2" rel="nofollow ugc">static link change</a></li>
<li><a href="https://github.com/notepad-plus-plus/wingup/commit/000e57426ffc39b38520a94fa0411bb6db02da92" rel="nofollow ugc">libcurl 8.19.0 update</a></li>
</ul>
]]></description><link>https://community.notepad-plus-plus.org/post/105246</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/105246</guid><dc:creator><![CDATA[xomx]]></dc:creator><pubDate>Wed, 15 Apr 2026 12:17:39 GMT</pubDate></item></channel></rss>