Release date:
2026-08-01 06:14:43 UTC
Description:
- CVE-2026-4873: do not reuse a clear-text STARTTLS connection when the new
transfer requires TLS, so an IMAP, SMTP or POP3 request that mandates TLS is
not sent over an unencrypted connection
- CVE-2026-6253: restore the proxy credentials set via options on every
redirect so credentials belonging to the first proxy are not disclosed to a
second, different proxy
- CVE-2026-6429: drop credentials that were not set through CURLOPT_USERNAME
on redirect so a netrc password established for the first host is not sent to
the redirect target over a reused connection or proxy
- CVE-2026-8924: trim trailing dots from the request and cookie domains before
the public suffix list check so a trailing-dot domain cannot set a super
cookie scoped to an unrelated site
Updated packages:
-
curl-7.76.1-31.el9_6.1.tuxcare.els16.x86_64.rpm
sha:7664a50371ca4b53549d51adf742b52c9df6cd6d60415f0b447ebe089a878318
-
curl-minimal-7.76.1-31.el9_6.1.tuxcare.els16.x86_64.rpm
sha:b98de1a8eafb91706d8e47f37210fb9f5151888f310de4b4699b31f0ce1bbb85
-
libcurl-7.76.1-31.el9_6.1.tuxcare.els16.i686.rpm
sha:23eb736e9b89058fa21c8018d61289845f6a686715464b23d63aeb0298f5a733
-
libcurl-7.76.1-31.el9_6.1.tuxcare.els16.x86_64.rpm
sha:ebcc9c28f4a8f8e10a0beba787d548811bcf7cd77c8cceb6c971c4da5c5382b3
-
libcurl-devel-7.76.1-31.el9_6.1.tuxcare.els16.i686.rpm
sha:fc221279e35b900a0feea063acc2927d61ce64534e6d75a990dc082b615b640b
-
libcurl-devel-7.76.1-31.el9_6.1.tuxcare.els16.x86_64.rpm
sha:a7c128666c2b7f66b421bd92c65122202ceac2be887ab6946d360cb28734f1d2
-
libcurl-minimal-7.76.1-31.el9_6.1.tuxcare.els16.i686.rpm
sha:988ae95bd08e42b6579506911f833175d476f34fce289f3bdc8265285a5d0990
-
libcurl-minimal-7.76.1-31.el9_6.1.tuxcare.els16.x86_64.rpm
sha:f8256fd12e189c07fadfe865d74d6cb9acabbb1041b5a1c981ca96ae86140a81
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.