SB20260925165 - openEuler 24.03 LTS SP4 update for curl



SB20260925165 - openEuler 24.03 LTS SP4 update for curl

Published: September 25, 2026

Security Bulletin ID SB20260925165
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 29% Low 71%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 vulnerabilities.


1) Authentication Bypass by Capture-replay (CVE-ID: CVE-2026-11856)

CWE-ID: CWE-294 - Authentication Bypass by Capture-replay

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication by replaying Digest authentication state.

The vulnerability exists due to authentication bypass by capture-replay in libcurl Digest authentication handling when reusing the same handle for a second transfer to a different HTTP origin. A remote attacker can receive a request containing an Authorization header intended for another origin to bypass authentication by replaying Digest authentication state.

The issue affects libcurl but not the curl command line tool. The leaked header does not reveal the other origin, and the exposed state allows replay only for the exact path of the captured request.


2) Improper restriction of communication channel to intended endpoints (CVE-ID: CVE-2026-13608)

CWE-ID: CWE-923 - Improper Restriction of Communication Channel to Intended Endpoints

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass LDAP server authentication.

The vulnerability exists due to improper restriction of communication channel to intended endpoints in the libcurl SASL negotiation for LDAP authentication when processing an incomplete OpenLDAP SASL handshake sequence. A remote attacker can inject a premature or shortcut response to bypass LDAP server authentication.

The issue only occurs when the OpenLDAP backend is used, and LDAPS is not affected.


3) Use-after-free (CVE-ID: CVE-2026-18924)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free.

The vulnerability exists due to use-after-free in libcurl HTTP/2 server push stream handling when processing an HTTPS HTTP/2 server push on a shared connection. A remote attacker can send a server push response sequence to trigger a use-after-free.

The issue affects libcurl only and requires HTTP/2 server push to be enabled and accepted by the application, along with connection sharing.


4) Exposure of Data Element to Wrong Session (CVE-ID: CVE-2026-19931)

CWE-ID: CWE-488 - Exposure of Data Element to Wrong Session

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause requests to be sent over another user's previously authenticated connection.

The vulnerability exists due to exposure of data element to wrong session in HTTP connection reuse for Negotiate authentication when reusing a connection established with empty credentials. A remote user can issue a request using blank credentials to cause requests to be sent over another user's previously authenticated connection.

This issue affects libcurl and the curl command line tool when Negotiate authentication is used with ambient credentials provided by SSPI or GSSAPI.


5) Improper Certificate Validation (CVE-ID: CVE-2026-80230)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass public key pinning.

The vulnerability exists due to improper certificate validation in libcurl and the curl command line tool when establishing TLS connections with CURLOPT_PINNEDPUBLICKEY configured and peer and host verification disabled. A remote attacker can present a connection without a server certificate to bypass public key pinning.

This issue is present only when curl is built with OpenSSL or a fork such as BoringSSL, AWS-LC, LibreSSL, or QuicTLS, and the insecure configuration also permits certificate-less connections.


6) Exposure of Data Element to Wrong Session (CVE-ID: CVE-2026-80231)

CWE-ID: CWE-488 - Exposure of Data Element to Wrong Session

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass intended certificate validation settings.

The vulnerability exists due to exposure of data element to wrong session in HTTPS connection reuse logic when reusing an existing connection for the same hostname with a different native CA store setting. A remote user can cause a transfer to use a previously established HTTPS connection to bypass intended certificate validation settings.

This issue affects Windows and macOS and also impacts the curl command line tool.


7) Insertion of Sensitive Information Into Sent Data (CVE-ID: CVE-2026-82209)

CWE-ID: CWE-201 - Insertion of Sensitive Information Into Sent Data

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to information exposure through sent data in the libcurl cookie handling logic when processing a Set-Cookie header with a Domain attribute matching an origin host that is itself a public suffix. A remote attacker can induce the client to send a previously stored cookie to an arbitrary sibling subdomain under the same public suffix to disclose sensitive information.

Exploitation requires libpsl support to be enabled, the apex public-suffix host to issue the cookie, and the client to subsequently contact an attacker-controlled sibling subdomain.


Remediation

Install update from vendor's website.