SB20260925169 - openEuler 20.03 LTS SP4 update for curl
Published: September 25, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Authentication Bypass by Capture-replay (CVE-ID: CVE-2026-11856)
CWE-ID: CWE-294 - Authentication Bypass by Capture-replay
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication by replaying Digest authentication state.
The vulnerability exists due to authentication bypass by capture-replay in libcurl Digest authentication handling when reusing the same handle for a second transfer to a different HTTP origin. A remote attacker can receive a request containing an Authorization header intended for another origin to bypass authentication by replaying Digest authentication state.
The issue affects libcurl but not the curl command line tool. The leaked header does not reveal the other origin, and the exposed state allows replay only for the exact path of the captured request.
2) Use-after-free (CVE-ID: CVE-2026-18924)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free.
The vulnerability exists due to use-after-free in libcurl HTTP/2 server push stream handling when processing an HTTPS HTTP/2 server push on a shared connection. A remote attacker can send a server push response sequence to trigger a use-after-free.
The issue affects libcurl only and requires HTTP/2 server push to be enabled and accepted by the application, along with connection sharing.
3) Exposure of Data Element to Wrong Session (CVE-ID: CVE-2026-19931)
CWE-ID: CWE-488 - Exposure of Data Element to Wrong Session
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause requests to be sent over another user's previously authenticated connection.
The vulnerability exists due to exposure of data element to wrong session in HTTP connection reuse for Negotiate authentication when reusing a connection established with empty credentials. A remote user can issue a request using blank credentials to cause requests to be sent over another user's previously authenticated connection.
This issue affects libcurl and the curl command line tool when Negotiate authentication is used with ambient credentials provided by SSPI or GSSAPI.
4) Improper Certificate Validation (CVE-ID: CVE-2026-80230)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass public key pinning.
The vulnerability exists due to improper certificate validation in libcurl and the curl command line tool when establishing TLS connections with CURLOPT_PINNEDPUBLICKEY configured and peer and host verification disabled. A remote attacker can present a connection without a server certificate to bypass public key pinning.
This issue is present only when curl is built with OpenSSL or a fork such as BoringSSL, AWS-LC, LibreSSL, or QuicTLS, and the insecure configuration also permits certificate-less connections.
5) Exposure of Data Element to Wrong Session (CVE-ID: CVE-2026-80231)
CWE-ID: CWE-488 - Exposure of Data Element to Wrong Session
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass intended certificate validation settings.
The vulnerability exists due to exposure of data element to wrong session in HTTPS connection reuse logic when reusing an existing connection for the same hostname with a different native CA store setting. A remote user can cause a transfer to use a previously established HTTPS connection to bypass intended certificate validation settings.
This issue affects Windows and macOS and also impacts the curl command line tool.
6) Insertion of Sensitive Information Into Sent Data (CVE-ID: CVE-2026-82209)
CWE-ID: CWE-201 - Insertion of Sensitive Information Into Sent Data
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to information exposure through sent data in the libcurl cookie handling logic when processing a Set-Cookie header with a Domain attribute matching an origin host that is itself a public suffix. A remote attacker can induce the client to send a previously stored cookie to an arbitrary sibling subdomain under the same public suffix to disclose sensitive information.
Exploitation requires libpsl support to be enabled, the apex public-suffix host to issue the cookie, and the client to subsequently contact an attacker-controlled sibling subdomain.
Remediation
Install update from vendor's website.