Yes, but a patch was committed to -current and 5.2-stable. You might like to follow the ports-changes mailing list, updates with security fixes are usually clearly identified.
Mike Korbakov <mike-...@yandex.ru> wrote: >Hi, All ! > >Is OpenBSD curl-7.26.0 affected by this issue: >http://curl.haxx.se/docs/adv_20130206.html > >Mike/