Release date:
2026-08-04 12:47:00 UTC
Description:
- CVE-2026-4873: do not reuse a clear-text STARTTLS connection when the new
transfer requires TLS, so an IMAP, SMTP or POP3 request that mandates TLS is
not sent over an unencrypted connection
- CVE-2026-6253: restore the proxy credentials set via options on every
redirect so credentials belonging to the first proxy are not disclosed to a
second, different proxy
- CVE-2026-6429: drop credentials that were not set through CURLOPT_USERNAME
on redirect so a netrc password established for the first host is not sent to
the redirect target over a reused connection or proxy
- CVE-2026-8924: trim trailing dots from the request and cookie domains before
the public suffix list check so a trailing-dot domain cannot set a super
cookie scoped to an unrelated site
Updated packages:
-
curl-7.76.1-31.el9_2.1.tuxcare.els16.x86_64.rpm
sha:0395587ca0deb03c90fdc93a28dce1870cedc8afaee86f348cf314a3a64d4802
-
curl-minimal-7.76.1-31.el9_2.1.tuxcare.els16.x86_64.rpm
sha:0a4f2a2dac3eef99acfd6e321e6454f0cf4f00782fa0e1af7f450506632c094d
-
libcurl-7.76.1-31.el9_2.1.tuxcare.els16.i686.rpm
sha:cc7a67fa3ac1c1375d3122e427db70330eb1a74444cdc67d75aa434090b7762a
-
libcurl-7.76.1-31.el9_2.1.tuxcare.els16.x86_64.rpm
sha:47149b6bea7d1a78d735a80268c8d1c7cc9fb28ea316bc2ea438aa0e4828d4fc
-
libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els16.i686.rpm
sha:e228ba4a6b6fc08a101eb1e639914af9c911bd0ea065b83ca797d9d9e3944424
-
libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els16.x86_64.rpm
sha:ad86822c6f6a2c059606b8ac49afc18fad23787d6c530f8852b1b319cce1389c
-
libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els16.i686.rpm
sha:1f66b6fa1ca1694fed28c775e8f3eba4044999db86e6182c05bac02996b5e090
-
libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els16.x86_64.rpm
sha:6ec454a68fad867f5a71fa94189de8174062723b9329aaa175c9cfbe5f88507d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.