[ALSA-2026:55439] Important: curl security update
Type:
security
Severity:
important
Release date:
2026-08-18
Description:
The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP. Security Fix(es): * curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication (CVE-2026-1965) * curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect (CVE-2026-3783) * curl: curl: Man-in-the-middle attack via SSH host key bypass (CVE-2026-9547) * curl: curl: Insecure connection establishment due to TLS configuration mismatch (CVE-2026-8286) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libcurl-minimal-7.76.1-40.el9_8.5.aarch64.rpm 07fabcfc0fac82677226e17f792b705b722e242a026abc449596faf500366483
aarch64 libcurl-7.76.1-40.el9_8.5.aarch64.rpm 470e0b176406f3374f2c303e1901f6ff5efed07ff61f256e10b7729ca0cbbbac
aarch64 curl-7.76.1-40.el9_8.5.aarch64.rpm 48ea25e32c33f9b8649973565f101f25e46b70afbce66c1c3c6af2160df73ade
aarch64 curl-minimal-7.76.1-40.el9_8.5.aarch64.rpm bc5b79d26b16dd576d1585a37c5bf969c94ebfa418af28978d2cca6dab6e36c2
aarch64 libcurl-devel-7.76.1-40.el9_8.5.aarch64.rpm ffcdf44f28c1120f141a53c27b871cf70bcee0d5a42f37bdb187e1fac55fd99b
i686 libcurl-devel-7.76.1-40.el9_8.5.i686.rpm 3ed08f9c67618cb026d86837cb12cc409457aa53461a4f1a5bef54c31ae0dc13
i686 libcurl-minimal-7.76.1-40.el9_8.5.i686.rpm 5a3f2114c450a30afad72d188b44e967e8f8e226b7cf0324e0a40759045f92ee
i686 libcurl-7.76.1-40.el9_8.5.i686.rpm bfdd6f9c6ad6e5c7b15e3543573a2886ab60fe2bfeab15d2eedca2d2d3bdec19
ppc64le curl-minimal-7.76.1-40.el9_8.5.ppc64le.rpm 2001fba4813cad1bbe1f4b9538d74c1b780d806733d81884756ac5abbe229b4f
ppc64le libcurl-devel-7.76.1-40.el9_8.5.ppc64le.rpm 2318cf33412ef71bc2b8f33692b412efaafb7a6f53c7f47cf8381167f3a6975f
ppc64le libcurl-minimal-7.76.1-40.el9_8.5.ppc64le.rpm 3f6b34752b6d0745607e8008961550a6b3b849e033f799ba2bc5dd9733ea3982
ppc64le curl-7.76.1-40.el9_8.5.ppc64le.rpm 787a00797a8aac1e346da9830106dd93f4cb7e9f1c19a322ac1a473ef8b8d2de
ppc64le libcurl-7.76.1-40.el9_8.5.ppc64le.rpm c976c0b3b1bd900c3d346da6200d0f9875791cdb95ecfd579f4029fb4ddebdad
s390x libcurl-minimal-7.76.1-40.el9_8.5.s390x.rpm 0f3540218e41b6fcef7e6695ecda9fdd07485571f624e187eb3322d40e8b170c
s390x libcurl-devel-7.76.1-40.el9_8.5.s390x.rpm 255422508aabe8ff8dd88efa9f58a38352d82e6fc7edbd3cd79bd17a1e3df172
s390x libcurl-7.76.1-40.el9_8.5.s390x.rpm 33648982304e4422d227627def18050ab52b06ab6379bac9634866865a40af8a
s390x curl-7.76.1-40.el9_8.5.s390x.rpm 8cec81884e09f1a1fb188b4e04fb3144d19ae4067da2a5c8bd71bf9a0ed48c7c
s390x curl-minimal-7.76.1-40.el9_8.5.s390x.rpm fe36131eb7bab3d46321ac4d2ac726d392e8cdd2e58c15102c0cd2a17f201712
x86_64 libcurl-7.76.1-40.el9_8.5.x86_64.rpm 09c07fff9f0ef212f51d1546f7a57cc1aa43c79e68f9c94bc7028724c420f384
x86_64 curl-7.76.1-40.el9_8.5.x86_64.rpm 21a4cc188bd3b06ba7d6e8caea74ee9d99f24ef9a2d8b4ea305d8ba143750f3d
x86_64 libcurl-devel-7.76.1-40.el9_8.5.x86_64.rpm 5408f135a95eb8711518edd31b9498f991a4fc98d20dbb23616b0d6d02516bf9
x86_64 curl-minimal-7.76.1-40.el9_8.5.x86_64.rpm 5709867e36ce6fa07ebeeb9aa6bfa540b8cd37fa00112033f9f37ffc086b0283
x86_64 libcurl-minimal-7.76.1-40.el9_8.5.x86_64.rpm 6b05e907a80f1bbb3566eb98cacd60f24780d6d70679ed78ede8aa8ac4251f25
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.