Release date:
2026-08-07 14:15:13 UTC
Description:
- CVE-2026-8927: detect proxy changes read from environment so Digest proxy
auth state is flushed instead of leaking the Proxy-Authorization header for
one proxy into a request sent through another
- CVE-2026-8286: require an SSL configuration match before reusing a pooled
connection for a clear-text transfer that may upgrade to TLS via STARTTLS
- CVE-2026-8932: include the client certificate key, key type, key password,
key blob and certificate type in SSL configuration matching so a connection
or cached TLS session established with different mTLS credentials is not
reused
Updated packages:
-
curl-8.3.0-1.amzn2.0.12.tuxcare.els5.x86_64.rpm
sha:2bc63268dd9158e81d011bef03f93228a8729ab14c2bd8826ea1e41cb517566b
-
libcurl-8.3.0-1.amzn2.0.12.tuxcare.els5.i686.rpm
sha:8bab41c5d9844c66b5e569d809cc3d2b161ab4c311f5b33eacfc750035a2b2c6
-
libcurl-8.3.0-1.amzn2.0.12.tuxcare.els5.x86_64.rpm
sha:1a8aef22ffc476e419a4446d86e2bd322578bc168c2c3ec4f4de76d91877129d
-
libcurl-devel-8.3.0-1.amzn2.0.12.tuxcare.els5.x86_64.rpm
sha:c46b3faa9ada1ab2de62873fce254f9467c2c1f2c6d53149db849eaeebb30d51
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.