<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:17:23 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:69125 — Important: curl security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:69125</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: curl, AlmaLinux:10: libcurl, AlmaLinux:10: libcurl-devel, AlmaLinux:10: libcurl-minimal&lt;/p&gt;
&lt;p&gt;The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse (CVE-2026-8932)
  * curl: curl: Information disclosure via incorrect .netrc password lookup (CVE-2026-8926)
  * curl: libcurl: Unauthorized connection reuse due to a logical error (CVE-2026-8458)
  * curl: curl: Cookie injection via malicious HTTP server using super cookies (CVE-2026-8924)
  * curl: curl: Information disclosure via incorrect Digest authentication header reuse (CVE-2026-11856)
  * libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials (CVE-2026-9079)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: curl, AlmaLinux:10: libcurl, AlmaLinux:10: libcurl-devel, AlmaLinux:10: libcurl-minimal&lt;/p&gt;
&lt;p&gt;The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse (CVE-2026-8932)
  * curl: curl: Information disclosure via incorrect .netrc password lookup (CVE-2026-8926)
  * curl: libcurl: Unauthorized connection reuse due to a logical error (CVE-2026-8458)
  * curl: curl: Cookie injection via malicious HTTP server using super cookies (CVE-2026-8924)
  * curl: curl: Information disclosure via incorrect Digest authentication header reuse (CVE-2026-11856)
  * libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials (CVE-2026-9079)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:69125</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-9079</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-9079</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: curl, Alpaquita:25: curl, Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: curl, Alpaquita:25: curl, Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-9079</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0797 — De multiples vulnérabilités ont été découvertes dans cURL et libcurl. Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0797</link>
      <description>certfr-2026-avi-0797</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0797</guid>
    </item>
    <item>
      <title>EUVD-2026-368433</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368433</link>
      <description>EUVD-2026-368433</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368433</guid>
    </item>
    <item>
      <title>fkie_cve-2026-9079</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-9079</link>
      <description>&lt;p&gt;libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-9079</guid>
    </item>
    <item>
      <title>GHSA-f4cv-xm48-3694</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f4cv-xm48-3694</link>
      <description>&lt;p&gt;libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f4cv-xm48-3694</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-9079 — stale proxy password leak</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-9079</link>
      <description>msrc_CVE-2026-9079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-9079</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11230-1 — curl-8.21.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11230-1</link>
      <description>&lt;p&gt;curl-8.21.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl-8.21.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11230-1</guid>
    </item>
    <item>
      <title>RHSA-2026:29017 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:29017</link>
      <description>&lt;p&gt;curl: curl: Insecure connection establishment due to TLS configuration mismatch curl: libcurl: Unauthorized connection reuse due to a logical error curl: curl: Cookie injection via malicious HTTP server using super cookies curl: curl: Double-free vulnerability in SASL authentication curl: curl: Information disclosure via incorrect .netrc password lookup curl: Information disclosure due to uncleared proxy authentication state libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback libcurl: libcurl: Information disclosure due to persistent Referer header curl: curl: Man-in-the-middle attack via SSH host key bypass curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse curl: curl: Denial of Service via WebSocket PING flood curl: curl: Information disclosure via incorrect Digest authentication header reuse curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl: curl: Insecure connection establishment due to TLS configuration mismatch curl: libcurl: Unauthorized connection reuse due to a logical error curl: curl: Cookie injection via malicious HTTP server using super cookies curl: curl: Double-free vulnerability in SASL authentication curl: curl: Information disclosure via incorrect .netrc password lookup curl: Information disclosure due to uncleared proxy authentication state libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback libcurl: libcurl: Information disclosure due to persistent Referer header curl: curl: Man-in-the-middle attack via SSH host key bypass curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse curl: curl: Denial of Service via WebSocket PING flood curl: curl: Information disclosure via incorrect Digest authentication header reuse curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:29017</guid>
    </item>
    <item>
      <title>RLSA-2026:69125 — Important: curl security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:69125</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: curl&lt;/p&gt;
&lt;p&gt;The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse (CVE-2026-8932)&lt;/p&gt;
&lt;p&gt;* curl: curl: Information disclosure via incorrect .netrc password lookup (CVE-2026-8926)&lt;/p&gt;
&lt;p&gt;* curl: libcurl: Unauthorized connection reuse due to a logical error (CVE-2026-8458)&lt;/p&gt;
&lt;p&gt;* curl: curl: Cookie injection via malicious HTTP server using super cookies (CVE-2026-8924)&lt;/p&gt;
&lt;p&gt;* curl: curl: Information disclosure via incorrect Digest authentication header reuse (CVE-2026-11856)&lt;/p&gt;
&lt;p&gt;* libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials (CVE-2026-9079)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: curl&lt;/p&gt;
&lt;p&gt;The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse (CVE-2026-8932)&lt;/p&gt;
&lt;p&gt;* curl: curl: Information disclosure via incorrect .netrc password lookup (CVE-2026-8926)&lt;/p&gt;
&lt;p&gt;* curl: libcurl: Unauthorized connection reuse due to a logical error (CVE-2026-8458)&lt;/p&gt;
&lt;p&gt;* curl: curl: Cookie injection via malicious HTTP server using super cookies (CVE-2026-8924)&lt;/p&gt;
&lt;p&gt;* curl: curl: Information disclosure via incorrect Digest authentication header reuse (CVE-2026-11856)&lt;/p&gt;
&lt;p&gt;* libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials (CVE-2026-9079)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:69125</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22553-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22553-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22553-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-9079</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-9079</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: curl, Ubuntu:26.04:LTS: curl&lt;/p&gt;
&lt;p&gt;libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: curl, Ubuntu:26.04:LTS: curl&lt;/p&gt;
&lt;p&gt;libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-9079</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2065 — cURL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2065</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2065</guid>
    </item>
  </channel>
</rss>
