[CLSA-2026:1785564870] curl: Fix of 4 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-01 06:14:43 UTC
Description:
- CVE-2026-4873: do not reuse a clear-text STARTTLS connection when the new transfer requires TLS, so an IMAP, SMTP or POP3 request that mandates TLS is not sent over an unencrypted connection - CVE-2026-6253: restore the proxy credentials set via options on every redirect so credentials belonging to the first proxy are not disclosed to a second, different proxy - CVE-2026-6429: drop credentials that were not set through CURLOPT_USERNAME on redirect so a netrc password established for the first host is not sent to the redirect target over a reused connection or proxy - CVE-2026-8924: trim trailing dots from the request and cookie domains before the public suffix list check so a trailing-dot domain cannot set a super cookie scoped to an unrelated site
Updated packages:
  • curl-7.76.1-31.el9_6.1.tuxcare.els16.x86_64.rpm
    sha:7664a50371ca4b53549d51adf742b52c9df6cd6d60415f0b447ebe089a878318
  • curl-minimal-7.76.1-31.el9_6.1.tuxcare.els16.x86_64.rpm
    sha:b98de1a8eafb91706d8e47f37210fb9f5151888f310de4b4699b31f0ce1bbb85
  • libcurl-7.76.1-31.el9_6.1.tuxcare.els16.i686.rpm
    sha:23eb736e9b89058fa21c8018d61289845f6a686715464b23d63aeb0298f5a733
  • libcurl-7.76.1-31.el9_6.1.tuxcare.els16.x86_64.rpm
    sha:ebcc9c28f4a8f8e10a0beba787d548811bcf7cd77c8cceb6c971c4da5c5382b3
  • libcurl-devel-7.76.1-31.el9_6.1.tuxcare.els16.i686.rpm
    sha:fc221279e35b900a0feea063acc2927d61ce64534e6d75a990dc082b615b640b
  • libcurl-devel-7.76.1-31.el9_6.1.tuxcare.els16.x86_64.rpm
    sha:a7c128666c2b7f66b421bd92c65122202ceac2be887ab6946d360cb28734f1d2
  • libcurl-minimal-7.76.1-31.el9_6.1.tuxcare.els16.i686.rpm
    sha:988ae95bd08e42b6579506911f833175d476f34fce289f3bdc8265285a5d0990
  • libcurl-minimal-7.76.1-31.el9_6.1.tuxcare.els16.x86_64.rpm
    sha:f8256fd12e189c07fadfe865d74d6cb9acabbb1041b5a1c981ca96ae86140a81
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.