<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:53:32.791872+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:69125</id>
    <title>ALSA-2026:69125 — Important: curl security update</title>
    <updated>2026-10-02T14:53:32.808474+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: curl, AlmaLinux:10: libcurl, AlmaLinux:10: libcurl-devel, AlmaLinux:10: libcurl-minimal</p>
<p>The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.</p>
<p>Security Fix(es):</p>
<p>* libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse (CVE-2026-8932)
  * curl: curl: Information disclosure via incorrect .netrc password lookup (CVE-2026-8926)
  * curl: libcurl: Unauthorized connection reuse due to a logical error (CVE-2026-8458)
  * curl: curl: Cookie injection via malicious HTTP server using super cookies (CVE-2026-8924)
  * curl: curl: Information disclosure via incorrect Digest authentication header reuse (CVE-2026-11856)
  * libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials (CVE-2026-9079)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:69125"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-8932</id>
    <title>BELL-CVE-2026-8932</title>
    <updated>2026-10-02T14:53:32.808541+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: curl, Alpaquita:25: curl, Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-8932"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0797</id>
    <title>certfr-2026-avi-0797 — De multiples vulnérabilités ont été découvertes dans cURL et libcurl. Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-02T14:53:32.808567+00:00</updated>
    <content>certfr-2026-avi-0797</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368432</id>
    <title>EUVD-2026-368432</title>
    <updated>2026-10-02T14:53:32.808583+00:00</updated>
    <content>EUVD-2026-368432</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368432"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-8932</id>
    <title>fkie_cve-2026-8932</title>
    <updated>2026-10-02T14:53:32.808594+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>libcurl would reuse a previously created connection even when some mTLS config
related option had been changed that should have prohibited reuse.</p>
<p>libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup. However, some TLS
settings related to client certificates were left out from the configuration
match checks, making them match too easily. In particular options related to
the private key.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-8932"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m7xm-hf59-w6rj</id>
    <title>GHSA-m7xm-hf59-w6rj</title>
    <updated>2026-10-02T14:53:32.808617+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>libcurl would reuse a previously created connection even when some mTLS config
related option had been changed that should have prohibited reuse.</p>
<p>libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup. However, some TLS
settings related to client certificates were left out from the configuration
match checks, making them match too easily. In particular options related to
the private key.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m7xm-hf59-w6rj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-8932</id>
    <title>msrc_CVE-2026-8932 — incomplete mTLS config matching in conn reuse</title>
    <updated>2026-10-02T14:53:32.808633+00:00</updated>
    <content>msrc_CVE-2026-8932</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-8932"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3675</id>
    <title>OESA-2026-3675 — curl security update</title>
    <updated>2026-10-02T14:53:32.808648+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: curl</p>
<p>cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.

Security Fix(es):</p>
<p>[&amp;apos;Hello friends,&amp;apos;, &amp;apos;CVE-2026-8286: wrong STARTTLS connection reuse (LOW)&amp;apos;, &amp;apos;CVE-2026-8458: wrong reuse for different services (LOW)&amp;apos;, &amp;apos;CVE-2026-8924: traling dot domain super cookie (LOW)&amp;apos;, &amp;apos;CVE-2026-8925: SASL double-free (MEDIUM)&amp;apos;, &amp;apos;CVE-2026-8926: password leak with netrc and user in URL (LOW)&amp;apos;, &amp;apos;CVE-2026-8927: env-set cross-proxy Digest auth state leak (MEDIUM)&amp;apos;, &amp;apos;CVE-2026-8932: incomplete mTLS config matching in conn reuse (LOW)&amp;apos;, &amp;apos;CVE-2026-9079: stale proxy password leak (MEDIUM)&amp;apos;, &amp;apos;CVE-2026-9080: UAF after pause in socket callback (LOW)&amp;apos;, &amp;apos;CVE-2026-9545: exposing HTTP/3 early data (LOW)&amp;apos;, &amp;apos;CVE-2026-9546: sending old referer (LOW)&amp;apos;, &amp;apos;CVE-2026-9547: SSH improper host validation (LOW)&amp;apos;, &amp;apos;CVE-2026-10536: HTTP/2 stream-dependency tree UAF (LOW)&amp;apos;, &amp;apos;CVE-2026-11352: QUIC zero-length UDP datagrams busy-loop (LOW)&amp;apos;, &amp;apos;CVE-2026-11564: Native CA trust persist (LOW)&amp;apos;, &amp;apos;CVE-2026-11586: WS Auto-PONG memory exhaustion (LOW)&amp;apos;, &amp;apos;CVE-2026-11856: cross-origin Digest auth state leak (MEDIUM)&amp;apos;, &amp;apos;CVE-2026-12064: proto-default skips SSH verification (LOW)&amp;apos;, &amp;apos;--\n\n / daniel.haxx.se ||&amp;apos;](CVE-2026-8932)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3675"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11230-1</id>
    <title>openSUSE-SU-2026:11230-1 — curl-8.21.0-1.1 on GA media</title>
    <updated>2026-10-02T14:53:32.808678+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl-8.21.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11230-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:29017</id>
    <title>RHSA-2026:29017 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T14:53:32.808700+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl: curl: Insecure connection establishment due to TLS configuration mismatch curl: libcurl: Unauthorized connection reuse due to a logical error curl: curl: Cookie injection via malicious HTTP server using super cookies curl: curl: Double-free vulnerability in SASL authentication curl: curl: Information disclosure via incorrect .netrc password lookup curl: Information disclosure due to uncleared proxy authentication state libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback libcurl: libcurl: Information disclosure due to persistent Referer header curl: curl: Man-in-the-middle attack via SSH host key bypass curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse curl: curl: Denial of Service via WebSocket PING flood curl: curl: Information disclosure via incorrect Digest authentication header reuse curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:29017"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:69125</id>
    <title>RLSA-2026:69125 — Important: curl security update</title>
    <updated>2026-10-02T14:53:32.808736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: curl</p>
<p>The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.</p>
<p>Security Fix(es):</p>
<p>* libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse (CVE-2026-8932)</p>
<p>* curl: curl: Information disclosure via incorrect .netrc password lookup (CVE-2026-8926)</p>
<p>* curl: libcurl: Unauthorized connection reuse due to a logical error (CVE-2026-8458)</p>
<p>* curl: curl: Cookie injection via malicious HTTP server using super cookies (CVE-2026-8924)</p>
<p>* curl: curl: Information disclosure via incorrect Digest authentication header reuse (CVE-2026-11856)</p>
<p>* libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials (CVE-2026-9079)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:69125"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8932</id>
    <title>UBUNTU-CVE-2026-8932</title>
    <updated>2026-10-02T14:53:32.808762+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: curl, Ubuntu:Pro:16.04:LTS: curl, Ubuntu:Pro:18.04:LTS: curl, Ubuntu:Pro:20.04:LTS: curl, Ubuntu:22.04:LTS: curl, Ubuntu:24.04:LTS: curl, Ubuntu:25.10: curl, Ubuntu:26.04:LTS: curl</p>
<p>libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8932"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2065</id>
    <title>WID-SEC-W-2026-2065 — cURL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:53:32.808789+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2065"/>
  </entry>
</feed>
