[CLSA-2026:1786112100] curl: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-07 14:15:13 UTC
Description:
- CVE-2026-8927: detect proxy changes read from environment so Digest proxy auth state is flushed instead of leaking the Proxy-Authorization header for one proxy into a request sent through another - CVE-2026-8286: require an SSL configuration match before reusing a pooled connection for a clear-text transfer that may upgrade to TLS via STARTTLS - CVE-2026-8932: include the client certificate key, key type, key password, key blob and certificate type in SSL configuration matching so a connection or cached TLS session established with different mTLS credentials is not reused
Updated packages:
  • curl-8.3.0-1.amzn2.0.12.tuxcare.els5.x86_64.rpm
    sha:2bc63268dd9158e81d011bef03f93228a8729ab14c2bd8826ea1e41cb517566b
  • libcurl-8.3.0-1.amzn2.0.12.tuxcare.els5.i686.rpm
    sha:8bab41c5d9844c66b5e569d809cc3d2b161ab4c311f5b33eacfc750035a2b2c6
  • libcurl-8.3.0-1.amzn2.0.12.tuxcare.els5.x86_64.rpm
    sha:1a8aef22ffc476e419a4446d86e2bd322578bc168c2c3ec4f4de76d91877129d
  • libcurl-devel-8.3.0-1.amzn2.0.12.tuxcare.els5.x86_64.rpm
    sha:c46b3faa9ada1ab2de62873fce254f9467c2c1f2c6d53149db849eaeebb30d51
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.