# Backporting libcurl updates?

**URL:** <https://discourse.julialang.org/t/backporting-libcurl-updates/139121>\
**Category:** General Usage\
**Created:** [August 31, 2026, 6:57pm UTC](https://discourse.julialang.org/t/backporting-libcurl-updates/139121 "2026-08-31T18:57:06Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![danielmatz](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/danielmatz/32/2285_2.png) [@danielmatz](https://discourse.julialang.org/u/danielmatz)\
**Post date:** [August 31, 2026, 6:57pm UTC](https://discourse.julialang.org/t/backporting-libcurl-updates/139121/1 "2026-08-31T18:57:07Z")

</div>

Our sys admins have flagged the libcurl that ships with Julia for security issues. They are asking us to update to at 8.21.0. I see that it got merged into master a little while ago: [curl: New version 8.21.0 - Pull Request #62251 - JuliaLang/julia - GitHub](https://github.com/JuliaLang/julia/pull/62251). I don’t see it in any of the “backport” issues, though. Is it possible for that to be backported as well? We were able to build from source and specify a different version of libcurl, but I’d love to keep using juliaup instead.

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [August 31, 2026, 7:01pm UTC](https://discourse.julialang.org/t/backporting-libcurl-updates/139121/2 "2026-08-31T19:01:03Z")

</div>

Those PRs are unlikely to be backportable as-is because they go through multiple intermediate updates, which breaks the automated backport pipeline. If you care about that, opening yourself the PR to do the update may be more effective
