UbuntuUpdates.org

Bugs fixes in "curl"

Origin Bug number Title Date fixed
CVE CVE-2026-8932 libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. li 2026-09-24
CVE CVE-2026-8458 libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 2026-09-24
CVE CVE-2026-6429 When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the f 2026-09-24
CVE CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentic 2026-09-24
CVE CVE-2026-82209 When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domai 2026-09-24
CVE CVE-2026-80230 When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL 2026-09-24
CVE CVE-2026-18924 A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-af 2026-09-24
Launchpad 2167779 Reverted security upload 8.20.0-2ubuntu4, broken checksrc and CVE-2026-8927 backport 2026-09-24
CVE CVE-2026-8458 libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 2026-09-24
CVE CVE-2026-8286 A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS 2026-09-24
CVE CVE-2026-6429 When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the f 2026-09-24
CVE CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentic 2026-09-24
CVE CVE-2026-82209 When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domai 2026-09-24
CVE CVE-2026-80230 When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL 2026-09-24
CVE CVE-2026-18924 A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-af 2026-09-24
CVE CVE-2026-13608 A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptogra 2026-09-24
Launchpad 2167779 Reverted security upload 8.20.0-2ubuntu4, broken checksrc and CVE-2026-8927 backport 2026-09-24
CVE CVE-2026-8458 libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 2026-09-24
CVE CVE-2026-11856 Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a diff 2026-09-24
CVE CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentic 2026-09-24



About   -   Send Feedback to @ubuntu_updates