The current curl rpm version 8.14.1 on AIX toolbox website is vulnerable per CVE-2025-10148 and CVE-2025-9086. Is there any timeline on when IBM will release the fixed version for this vulnerability.
as the vulnerabilities CVE-2025-10148 and CVE-2025-9086 were recently identified and are not yet patched in the official IBM repositories. You can monitor the AIX Toolbox website for updates
Thank you
Hi Ed Var,
This is in our to-do list and hopefully be done in a week or so.