RHSA-2026:69125HighCVSS 8.1

Red Hat Security Advisory: curl security update

Published
September 21, 2026
Last Modified
September 28, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-8458 — curl: libcurl: Unauthorized connection reuse due to a logical error CVE-2026-8924 — curl: curl: Cookie injection via malicious HTTP server using super cookies CVE-2026-8926 — curl: curl: Information disclosure via incorrect .netrc password lookup CVE-2026-8932 — libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse CVE-2026-9079 — libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials CVE-2026-11856 — curl: curl: Information disclosure via incorrect Digest authentication header reuse

🎯 Affected products51

  • Red Hat Enterprise Linux AppStream (v. 10)
  • Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-0:8.12.1-4.el10_2.6.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-0:8.12.1-4.el10_2.6.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-0:8.12.1-4.el10_2.6.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-0:8.12.1-4.el10_2.6.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-0:8.12.1-4.el10_2.6.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-debuginfo-0:8.12.1-4.el10_2.6.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • curl-debuginfo-0:8.12.1-4.el10_2.6.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-debuginfo-0:8.12.1-4.el10_2.6.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • curl-debuginfo-0:8.12.1-4.el10_2.6.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-debuginfo-0:8.12.1-4.el10_2.6.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • curl-debuginfo-0:8.12.1-4.el10_2.6.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-debuginfo-0:8.12.1-4.el10_2.6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • curl-debuginfo-0:8.12.1-4.el10_2.6.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-debugsource-0:8.12.1-4.el10_2.6.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • curl-debugsource-0:8.12.1-4.el10_2.6.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-debugsource-0:8.12.1-4.el10_2.6.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • curl-debugsource-0:8.12.1-4.el10_2.6.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-debugsource-0:8.12.1-4.el10_2.6.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • curl-debugsource-0:8.12.1-4.el10_2.6.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • curl-debugsource-0:8.12.1-4.el10_2.6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • curl-debugsource-0:8.12.1-4.el10_2.6.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • libcurl-0:8.12.1-4.el10_2.6.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • libcurl-0:8.12.1-4.el10_2.6.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • libcurl-0:8.12.1-4.el10_2.6.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • libcurl-0:8.12.1-4.el10_2.6.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • libcurl-debuginfo-0:8.12.1-4.el10_2.6.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • libcurl-debuginfo-0:8.12.1-4.el10_2.6.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • libcurl-debuginfo-0:8.12.1-4.el10_2.6.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • +21 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Do not use trailing-dot hostnames in URLs passed to curl. Trailing dots are uncommon and incompatible with TLS SNI. Upgrade to curl 8.21.0 to resolve Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Correct usage of the library: Create a fresh handle for a different origin, or explicitly clear authentication-related state before reuse: ```c // req.A curl = curl_easy_init(); ... curl_easy_cleanup(curl); // req.B curl = curl_easy_init(); ... curl_easy_cleanup(curl); ``` Fixed in libcurl 8.21.0; affected range: 7.10.6 – 8.20.0

🔗 References (9)