{"id":"USN-8820-1","summary":"curl vulnerabilities","details":"Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for\nLDAP authentication in certain circumstances. A machine-in-the-middle\nattacker could possibly use this issue to bypass peer validation. This\nissue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.\n(CVE-2026-13608)\n\nStephan Zeisberg discovered that curl incorrectly handled HTTP/2 Server\nPush streams when sharing connections between handles. A remote attacker\ncould possibly use this issue to cause curl to crash, resulting in a denial\nof service, or execute arbitrary code. (CVE-2026-18924)\n\nStanislav Fort discovered that curl incorrectly managed the lifetime of\npooled TLS connections when using the multi interface. An attacker could\npossibly use this issue to cause curl to crash, resulting in a denial of\nservice, or execute arbitrary code. This issue only affected Ubuntu 26.04\nLTS. (CVE-2026-80229)\n\nStanislav Fort discovered that curl did not properly enforce public key\npinning when certificate verification was disabled in certain\ncircumstances. A remote attacker could possibly use this issue to bypass\npinning checks and cause curl to accept connections that should have been\nrejected. (CVE-2026-80230)\n\nStanislav Fort discovered that curl incorrectly handled the Secure\nattribute of cookies in certain circumstances. A remote attacker could\npossibly use this issue to obtain sensitive information. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-80255)\n\nStanislav Fort discovered that curl did not properly enforce Public\nSuffix List boundaries when handling cookies in certain circumstances. A\nremote attacker could possibly use this issue to cause cookies to be sent\nto unrelated domains, resulting in sensitive information being exposed.\nThis issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-82209)\n\nAdy Elouej discovered that curl did not clear proxy authentication state\nbetween requests when reusing a handle with environment-variable proxy\nconfiguration. A remote attacker could possibly use this issue to obtain\nsensitive credentials. This issue was previously fixed in USN-8487-1, but\nthat fix was incomplete for Ubuntu 16.04 LTS. (CVE-2026-8927)","modified":"2026-09-25T06:43:34.384633789Z","published":"2026-09-24T20:13:19Z","upstream":["CVE-2026-13608","CVE-2026-18924","CVE-2026-80229","CVE-2026-80230","CVE-2026-80255","CVE-2026-82209","CVE-2026-8927","CVE-2026-9080","UBUNTU-CVE-2026-13608","UBUNTU-CVE-2026-18924","UBUNTU-CVE-2026-80229","UBUNTU-CVE-2026-80230","UBUNTU-CVE-2026-80255","UBUNTU-CVE-2026-82209","UBUNTU-CVE-2026-8927","UBUNTU-CVE-2026-9080"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8820-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-8927"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-9080"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-13608"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-18924"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-80229"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-80230"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-80255"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-82209"}],"affected":[{"package":{"name":"curl","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/curl?arch=source&distro=esm-infra-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.47.0-1ubuntu2.19+esm20"}]}],"versions":["7.43.0-1ubuntu2","7.45.0-1ubuntu1","7.46.0-1ubuntu1","7.47.0-1ubuntu1","7.47.0-1ubuntu2","7.47.0-1ubuntu2.1","7.47.0-1ubuntu2.2","7.47.0-1ubuntu2.3","7.47.0-1ubuntu2.4","7.47.0-1ubuntu2.5","7.47.0-1ubuntu2.6","7.47.0-1ubuntu2.7","7.47.0-1ubuntu2.8","7.47.0-1ubuntu2.9","7.47.0-1ubuntu2.11","7.47.0-1ubuntu2.12","7.47.0-1ubuntu2.13","7.47.0-1ubuntu2.14","7.47.0-1ubuntu2.15","7.47.0-1ubuntu2.16","7.47.0-1ubuntu2.18","7.47.0-1ubuntu2.19","7.47.0-1ubuntu2.19+esm1","7.47.0-1ubuntu2.19+esm2","7.47.0-1ubuntu2.19+esm3","7.47.0-1ubuntu2.19+esm4","7.47.0-1ubuntu2.19+esm5","7.47.0-1ubuntu2.19+esm6","7.47.0-1ubuntu2.19+esm7","7.47.0-1ubuntu2.19+esm8","7.47.0-1ubuntu2.19+esm9","7.47.0-1ubuntu2.19+esm10","7.47.0-1ubuntu2.19+esm11","7.47.0-1ubuntu2.19+esm12","7.47.0-1ubuntu2.19+esm13","7.47.0-1ubuntu2.19+esm15","7.47.0-1ubuntu2.19+esm16","7.47.0-1ubuntu2.19+esm17","7.47.0-1ubuntu2.19+esm18"],"ecosystem_specific":{"binaries":[{"binary_name":"curl","binary_version":"7.47.0-1ubuntu2.19+esm20"},{"binary_version":"7.47.0-1ubuntu2.19+esm20","binary_name":"libcurl3"},{"binary_version":"7.47.0-1ubuntu2.19+esm20","binary_name":"libcurl3-gnutls"},{"binary_name":"libcurl3-nss","binary_version":"7.47.0-1ubuntu2.19+esm20"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8820-1.json"}},{"package":{"name":"curl","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/curl?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.58.0-2ubuntu3.24+esm14"}]}],"versions":["7.55.1-1ubuntu2","7.55.1-1ubuntu2.1","7.57.0-1ubuntu1","7.58.0-2ubuntu1","7.58.0-2ubuntu2","7.58.0-2ubuntu3","7.58.0-2ubuntu3.1","7.58.0-2ubuntu3.2","7.58.0-2ubuntu3.3","7.58.0-2ubuntu3.5","7.58.0-2ubuntu3.6","7.58.0-2ubuntu3.7","7.58.0-2ubuntu3.8","7.58.0-2ubuntu3.9","7.58.0-2ubuntu3.10","7.58.0-2ubuntu3.12","7.58.0-2ubuntu3.13","7.58.0-2ubuntu3.14","7.58.0-2ubuntu3.15","7.58.0-2ubuntu3.16","7.58.0-2ubuntu3.17","7.58.0-2ubuntu3.18","7.58.0-2ubuntu3.19","7.58.0-2ubuntu3.20","7.58.0-2ubuntu3.21","7.58.0-2ubuntu3.22","7.58.0-2ubuntu3.23","7.58.0-2ubuntu3.24","7.58.0-2ubuntu3.24+esm1","7.58.0-2ubuntu3.24+esm2","7.58.0-2ubuntu3.24+esm3","7.58.0-2ubuntu3.24+esm4","7.58.0-2ubuntu3.24+esm5","7.58.0-2ubuntu3.24+esm7","7.58.0-2ubuntu3.24+esm8","7.58.0-2ubuntu3.24+esm9","7.58.0-2ubuntu3.24+esm10","7.58.0-2ubuntu3.24+esm11","7.58.0-2ubuntu3.24+esm12"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_name":"curl","binary_version":"7.58.0-2ubuntu3.24+esm14"},{"binary_version":"7.58.0-2ubuntu3.24+esm14","binary_name":"libcurl3-gnutls"},{"binary_name":"libcurl3-nss","binary_version":"7.58.0-2ubuntu3.24+esm14"},{"binary_name":"libcurl4","binary_version":"7.58.0-2ubuntu3.24+esm14"}]},"database_specific":{"cves_map":{"cves":[],"ecosystem":"Ubuntu:Pro:18.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8820-1.json"}},{"package":{"name":"curl","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/curl?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.68.0-1ubuntu2.25+esm9"}]}],"versions":["7.65.3-1ubuntu3","7.65.3-1ubuntu4","7.66.0-1ubuntu1","7.67.0-2ubuntu1","7.68.0-1ubuntu1","7.68.0-1ubuntu2","7.68.0-1ubuntu2.1","7.68.0-1ubuntu2.2","7.68.0-1ubuntu2.4","7.68.0-1ubuntu2.5","7.68.0-1ubuntu2.6","7.68.0-1ubuntu2.7","7.68.0-1ubuntu2.10","7.68.0-1ubuntu2.11","7.68.0-1ubuntu2.12","7.68.0-1ubuntu2.13","7.68.0-1ubuntu2.14","7.68.0-1ubuntu2.15","7.68.0-1ubuntu2.16","7.68.0-1ubuntu2.18","7.68.0-1ubuntu2.19","7.68.0-1ubuntu2.20","7.68.0-1ubuntu2.21","7.68.0-1ubuntu2.22","7.68.0-1ubuntu2.23","7.68.0-1ubuntu2.24","7.68.0-1ubuntu2.25","7.68.0-1ubuntu2.25+esm2","7.68.0-1ubuntu2.25+esm3","7.68.0-1ubuntu2.25+esm4","7.68.0-1ubuntu2.25+esm5","7.68.0-1ubuntu2.25+esm6","7.68.0-1ubuntu2.25+esm7"],"ecosystem_specific":{"binaries":[{"binary_name":"curl","binary_version":"7.68.0-1ubuntu2.25+esm9"},{"binary_name":"libcurl3-gnutls","binary_version":"7.68.0-1ubuntu2.25+esm9"},{"binary_name":"libcurl3-nss","binary_version":"7.68.0-1ubuntu2.25+esm9"},{"binary_name":"libcurl4","binary_version":"7.68.0-1ubuntu2.25+esm9"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[],"ecosystem":"Ubuntu:Pro:20.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8820-1.json"}},{"package":{"name":"curl","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/curl?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.81.0-1ubuntu1.29"}]}],"versions":["7.74.0-1.3ubuntu2","7.74.0-1.3ubuntu3","7.80.0-3","7.81.0-1","7.81.0-1ubuntu1.1","7.81.0-1ubuntu1.2","7.81.0-1ubuntu1.3","7.81.0-1ubuntu1.4","7.81.0-1ubuntu1.6","7.81.0-1ubuntu1.7","7.81.0-1ubuntu1.8","7.81.0-1ubuntu1.10","7.81.0-1ubuntu1.11","7.81.0-1ubuntu1.13","7.81.0-1ubuntu1.14","7.81.0-1ubuntu1.15","7.81.0-1ubuntu1.16","7.81.0-1ubuntu1.17","7.81.0-1ubuntu1.18","7.81.0-1ubuntu1.19","7.81.0-1ubuntu1.20","7.81.0-1ubuntu1.21","7.81.0-1ubuntu1.22","7.81.0-1ubuntu1.23","7.81.0-1ubuntu1.24","7.81.0-1ubuntu1.25","7.81.0-1ubuntu1.26","7.81.0-1ubuntu1.27"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"curl","binary_version":"7.81.0-1ubuntu1.29"},{"binary_version":"7.81.0-1ubuntu1.29","binary_name":"libcurl3-gnutls"},{"binary_version":"7.81.0-1ubuntu1.29","binary_name":"libcurl3-nss"},{"binary_name":"libcurl4","binary_version":"7.81.0-1ubuntu1.29"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8820-1.json","cves_map":{"ecosystem":"Ubuntu:22.04:LTS","cves":[]}}},{"package":{"name":"curl","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/curl?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.5.0-2ubuntu10.15"}]}],"versions":["8.2.1-1ubuntu3","8.2.1-1ubuntu3.1","8.4.0-2ubuntu1","8.5.0-2ubuntu1","8.5.0-2ubuntu2","8.5.0-2ubuntu8","8.5.0-2ubuntu9","8.5.0-2ubuntu10","8.5.0-2ubuntu10.1","8.5.0-2ubuntu10.2","8.5.0-2ubuntu10.3","8.5.0-2ubuntu10.4","8.5.0-2ubuntu10.5","8.5.0-2ubuntu10.6","8.5.0-2ubuntu10.7","8.5.0-2ubuntu10.8","8.5.0-2ubuntu10.9","8.5.0-2ubuntu10.10","8.5.0-2ubuntu10.11","8.5.0-2ubuntu10.12","8.5.0-2ubuntu10.13"],"ecosystem_specific":{"binaries":[{"binary_version":"8.5.0-2ubuntu10.15","binary_name":"curl"},{"binary_name":"libcurl3t64-gnutls","binary_version":"8.5.0-2ubuntu10.15"},{"binary_version":"8.5.0-2ubuntu10.15","binary_name":"libcurl4t64"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8820-1.json","cves_map":{"cves":[],"ecosystem":"Ubuntu:24.04:LTS"}}},{"package":{"name":"curl","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/curl?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.18.0-1ubuntu2.7"}]}],"versions":["8.14.1-2ubuntu1","8.17.0-1ubuntu1","8.18.0-1ubuntu1","8.18.0-1ubuntu2","8.18.0-1ubuntu2.1","8.18.0-1ubuntu2.2","8.18.0-1ubuntu2.3","8.18.0-1ubuntu2.4","8.18.0-1ubuntu2.5"],"ecosystem_specific":{"binaries":[{"binary_name":"curl","binary_version":"8.18.0-1ubuntu2.7"},{"binary_version":"8.18.0-1ubuntu2.7","binary_name":"libcurl3t64-gnutls"},{"binary_version":"8.18.0-1ubuntu2.7","binary_name":"libcurl4t64"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8820-1.json","cves_map":{"cves":[],"ecosystem":"Ubuntu:26.04:LTS"}}}],"schema_version":"1.9.0"}