[CLSA-2026:1785847606] curl: Fix of 4 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-04 12:47:00 UTC
Description:
- CVE-2026-4873: do not reuse a clear-text STARTTLS connection when the new transfer requires TLS, so an IMAP, SMTP or POP3 request that mandates TLS is not sent over an unencrypted connection - CVE-2026-6253: restore the proxy credentials set via options on every redirect so credentials belonging to the first proxy are not disclosed to a second, different proxy - CVE-2026-6429: drop credentials that were not set through CURLOPT_USERNAME on redirect so a netrc password established for the first host is not sent to the redirect target over a reused connection or proxy - CVE-2026-8924: trim trailing dots from the request and cookie domains before the public suffix list check so a trailing-dot domain cannot set a super cookie scoped to an unrelated site
Updated packages:
  • curl-7.76.1-31.el9_2.1.tuxcare.els16.x86_64.rpm
    sha:0395587ca0deb03c90fdc93a28dce1870cedc8afaee86f348cf314a3a64d4802
  • curl-minimal-7.76.1-31.el9_2.1.tuxcare.els16.x86_64.rpm
    sha:0a4f2a2dac3eef99acfd6e321e6454f0cf4f00782fa0e1af7f450506632c094d
  • libcurl-7.76.1-31.el9_2.1.tuxcare.els16.i686.rpm
    sha:cc7a67fa3ac1c1375d3122e427db70330eb1a74444cdc67d75aa434090b7762a
  • libcurl-7.76.1-31.el9_2.1.tuxcare.els16.x86_64.rpm
    sha:47149b6bea7d1a78d735a80268c8d1c7cc9fb28ea316bc2ea438aa0e4828d4fc
  • libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els16.i686.rpm
    sha:e228ba4a6b6fc08a101eb1e639914af9c911bd0ea065b83ca797d9d9e3944424
  • libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els16.x86_64.rpm
    sha:ad86822c6f6a2c059606b8ac49afc18fad23787d6c530f8852b1b319cce1389c
  • libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els16.i686.rpm
    sha:1f66b6fa1ca1694fed28c775e8f3eba4044999db86e6182c05bac02996b5e090
  • libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els16.x86_64.rpm
    sha:6ec454a68fad867f5a71fa94189de8174062723b9329aaa175c9cfbe5f88507d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.