Skip to main content
EPSS 0.7%top 49%

curl security update (CVE-2026-11856)

0
Critical
Published: 09/25/2026 (09/25/2026, 01:28:47 UTC)
Source: GCVE Database
Product: curl

Description

cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols. Security Fix(es): Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.(CVE-2026-11856) A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.(CVE-2026-13608) A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.(CVE-2026-18924) A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.(CVE-2026-19931) When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.(CVE-2026-80230) A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.(CVE-2026-80231) When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`). Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`).(CVE-2026-82209)

CVSS v3.1

Score 9.8critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected software

Ubuntu:Pro:14.04:LTSmore threats →ghsa
curl
pkg:deb/ubuntu/curl?arch=source&distro=esm-infra-legacy/trusty
Affected versions
<7.35.0-1ubuntu2.20+esm22=7.32.0-1ubuntu1=7.33.0-1ubuntu1=7.34.0-1ubuntu1=7.35.0-1ubuntu1=7.35.0-1ubuntu2=7.35.0-1ubuntu2.1=7.35.0-1ubuntu2.2=7.35.0-1ubuntu2.3=7.35.0-1ubuntu2.5=7.35.0-1ubuntu2.6=7.35.0-1ubuntu2.7=7.35.0-1ubuntu2.8=7.35.0-1ubuntu2.9=7.35.0-1ubuntu2.10=7.35.0-1ubuntu2.11=7.35.0-1ubuntu2.12=7.35.0-1ubuntu2.13=7.35.0-1ubuntu2.14=7.35.0-1ubuntu2.15=7.35.0-1ubuntu2.16=7.35.0-1ubuntu2.17=7.35.0-1ubuntu2.19=7.35.0-1ubuntu2.20=7.35.0-1ubuntu2.20+esm2=7.35.0-1ubuntu2.20+esm3=7.35.0-1ubuntu2.20+esm4=7.35.0-1ubuntu2.20+esm5=7.35.0-1ubuntu2.20+esm6=7.35.0-1ubuntu2.20+esm7=7.35.0-1ubuntu2.20+esm8=7.35.0-1ubuntu2.20+esm9=7.35.0-1ubuntu2.20+esm10=7.35.0-1ubuntu2.20+esm11=7.35.0-1ubuntu2.20+esm12=7.35.0-1ubuntu2.20+esm13=7.35.0-1ubuntu2.20+esm14=7.35.0-1ubuntu2.20+esm15=7.35.0-1ubuntu2.20+esm16=7.35.0-1ubuntu2.20+esm17=7.35.0-1ubuntu2.20+esm18=7.35.0-1ubuntu2.20+esm19=7.35.0-1ubuntu2.20+esm20=7.35.0-1ubuntu2.20+esm21
Ubuntu:Pro:16.04:LTSmore threats →ghsa
curl
pkg:deb/ubuntu/curl?arch=source&distro=esm-infra-legacy/xenial
Affected versions
<7.47.0-1ubuntu2.19+esm18=7.43.0-1ubuntu2=7.45.0-1ubuntu1=7.46.0-1ubuntu1=7.47.0-1ubuntu1=7.47.0-1ubuntu2=7.47.0-1ubuntu2.1=7.47.0-1ubuntu2.2=7.47.0-1ubuntu2.3=7.47.0-1ubuntu2.4=7.47.0-1ubuntu2.5=7.47.0-1ubuntu2.6=7.47.0-1ubuntu2.7=7.47.0-1ubuntu2.8=7.47.0-1ubuntu2.9=7.47.0-1ubuntu2.11=7.47.0-1ubuntu2.12=7.47.0-1ubuntu2.13=7.47.0-1ubuntu2.14=7.47.0-1ubuntu2.15=7.47.0-1ubuntu2.16=7.47.0-1ubuntu2.18=7.47.0-1ubuntu2.19=7.47.0-1ubuntu2.19+esm1=7.47.0-1ubuntu2.19+esm2=7.47.0-1ubuntu2.19+esm3=7.47.0-1ubuntu2.19+esm4=7.47.0-1ubuntu2.19+esm5=7.47.0-1ubuntu2.19+esm6=7.47.0-1ubuntu2.19+esm7=7.47.0-1ubuntu2.19+esm8=7.47.0-1ubuntu2.19+esm9=7.47.0-1ubuntu2.19+esm10=7.47.0-1ubuntu2.19+esm11=7.47.0-1ubuntu2.19+esm12=7.47.0-1ubuntu2.19+esm13=7.47.0-1ubuntu2.19+esm15=7.47.0-1ubuntu2.19+esm16=7.47.0-1ubuntu2.19+esm17
Ubuntu:Pro:18.04:LTSmore threats →ghsa
curl
pkg:deb/ubuntu/curl?arch=source&distro=esm-infra/bionic
Affected versions
<7.58.0-2ubuntu3.24+esm11=7.55.1-1ubuntu2=7.55.1-1ubuntu2.1=7.57.0-1ubuntu1=7.58.0-2ubuntu1=7.58.0-2ubuntu2=7.58.0-2ubuntu3=7.58.0-2ubuntu3.1=7.58.0-2ubuntu3.2=7.58.0-2ubuntu3.3=7.58.0-2ubuntu3.5=7.58.0-2ubuntu3.6=7.58.0-2ubuntu3.7=7.58.0-2ubuntu3.8=7.58.0-2ubuntu3.9=7.58.0-2ubuntu3.10=7.58.0-2ubuntu3.12=7.58.0-2ubuntu3.13=7.58.0-2ubuntu3.14=7.58.0-2ubuntu3.15=7.58.0-2ubuntu3.16=7.58.0-2ubuntu3.17=7.58.0-2ubuntu3.18=7.58.0-2ubuntu3.19=7.58.0-2ubuntu3.20=7.58.0-2ubuntu3.21=7.58.0-2ubuntu3.22=7.58.0-2ubuntu3.23=7.58.0-2ubuntu3.24=7.58.0-2ubuntu3.24+esm1=7.58.0-2ubuntu3.24+esm2=7.58.0-2ubuntu3.24+esm3=7.58.0-2ubuntu3.24+esm4=7.58.0-2ubuntu3.24+esm5=7.58.0-2ubuntu3.24+esm7=7.58.0-2ubuntu3.24+esm8=7.58.0-2ubuntu3.24+esm9=7.58.0-2ubuntu3.24+esm10
Ubuntu:Pro:20.04:LTSmore threats →ghsa
curl
pkg:deb/ubuntu/curl?arch=source&distro=esm-infra/focal
Affected versions
<7.68.0-1ubuntu2.25+esm6=7.65.3-1ubuntu3=7.65.3-1ubuntu4=7.66.0-1ubuntu1=7.67.0-2ubuntu1=7.68.0-1ubuntu1=7.68.0-1ubuntu2=7.68.0-1ubuntu2.1=7.68.0-1ubuntu2.2=7.68.0-1ubuntu2.4=7.68.0-1ubuntu2.5=7.68.0-1ubuntu2.6=7.68.0-1ubuntu2.7=7.68.0-1ubuntu2.10=7.68.0-1ubuntu2.11=7.68.0-1ubuntu2.12=7.68.0-1ubuntu2.13=7.68.0-1ubuntu2.14=7.68.0-1ubuntu2.15=7.68.0-1ubuntu2.16=7.68.0-1ubuntu2.18=7.68.0-1ubuntu2.19=7.68.0-1ubuntu2.20=7.68.0-1ubuntu2.21=7.68.0-1ubuntu2.22=7.68.0-1ubuntu2.23=7.68.0-1ubuntu2.24=7.68.0-1ubuntu2.25=7.68.0-1ubuntu2.25+esm2=7.68.0-1ubuntu2.25+esm3=7.68.0-1ubuntu2.25+esm4=7.68.0-1ubuntu2.25+esm5
Ubuntu:22.04:LTSmore threats →ghsa
curl
pkg:deb/ubuntu/curl?arch=source&distro=jammy
Affected versions
<7.81.0-1ubuntu1.26=7.74.0-1.3ubuntu2=7.74.0-1.3ubuntu3=7.80.0-3=7.81.0-1=7.81.0-1ubuntu1.1=7.81.0-1ubuntu1.2=7.81.0-1ubuntu1.3=7.81.0-1ubuntu1.4=7.81.0-1ubuntu1.6=7.81.0-1ubuntu1.7=7.81.0-1ubuntu1.8=7.81.0-1ubuntu1.10=7.81.0-1ubuntu1.11=7.81.0-1ubuntu1.13=7.81.0-1ubuntu1.14=7.81.0-1ubuntu1.15=7.81.0-1ubuntu1.16=7.81.0-1ubuntu1.17=7.81.0-1ubuntu1.18=7.81.0-1ubuntu1.19=7.81.0-1ubuntu1.20=7.81.0-1ubuntu1.21=7.81.0-1ubuntu1.22=7.81.0-1ubuntu1.23=7.81.0-1ubuntu1.24=7.81.0-1ubuntu1.25
Ubuntu:24.04:LTSmore threats →ghsa
curl
pkg:deb/ubuntu/curl?arch=source&distro=noble
Affected versions
<8.5.0-2ubuntu10.12=8.2.1-1ubuntu3=8.2.1-1ubuntu3.1=8.4.0-2ubuntu1=8.5.0-2ubuntu1=8.5.0-2ubuntu2=8.5.0-2ubuntu8=8.5.0-2ubuntu9=8.5.0-2ubuntu10=8.5.0-2ubuntu10.1=8.5.0-2ubuntu10.2=8.5.0-2ubuntu10.3=8.5.0-2ubuntu10.4=8.5.0-2ubuntu10.5=8.5.0-2ubuntu10.6=8.5.0-2ubuntu10.7=8.5.0-2ubuntu10.8=8.5.0-2ubuntu10.9=8.5.0-2ubuntu10.10=8.5.0-2ubuntu10.11
Ubuntu:25.10more threats →ghsa
curl
pkg:deb/ubuntu/curl?arch=source&distro=questing
Affected versions
=8.12.1-3ubuntu1=8.13.0-5ubuntu1=8.14.1-1ubuntu2=8.14.1-1ubuntu3=8.14.1-2ubuntu1=8.14.1-2ubuntu1.1=8.14.1-2ubuntu1.2=8.14.1-2ubuntu1.3=8.14.1-2ubuntu1.4=8.14.1-2ubuntu1.5
Ubuntu:26.04:LTSmore threats →ghsa
curl
pkg:deb/ubuntu/curl?arch=source&distro=resolute
Affected versions
<8.18.0-1ubuntu2.4=8.14.1-2ubuntu1=8.17.0-1ubuntu1=8.18.0-1ubuntu1=8.18.0-1ubuntu2=8.18.0-1ubuntu2.1=8.18.0-1ubuntu2.2=8.18.0-1ubuntu2.3
openEuler:24.03-LTS-SP4more threats →ghsa
curl
pkg:rpm/openEuler/curl&distro=openEuler-24.03-LTS-SP4
Affected versions
<8.4.0-37.oe2403sp4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 08:50:29 UTC

Technical Analysis

CVE-2026-11856 describes a flaw in libcurl's handling of Digest authentication when reusing a handle for transfers to different HTTP origins. Specifically, the Authorization header meant for the first origin (hostA) is incorrectly reused and sent to a second, different origin (hostB). This behavior can cause sensitive authentication information to be exposed to unintended servers. The vulnerability affects numerous versions of curl, including but not limited to versions prior to 8.18.0-1ubuntu2.4 on Ubuntu 26.04 LTS and earlier versions on other Ubuntu LTS releases. The issue was discovered and patched, with updates provided by Ubuntu and available via standard system updates or Ubuntu Pro for extended support versions.

Potential Impact

A remote attacker could exploit this vulnerability to obtain sensitive information by tricking libcurl into sending authentication credentials intended for one host to another host. This could lead to unauthorized disclosure of credentials and potentially compromise confidentiality, integrity, and availability of communications relying on libcurl with Digest authentication.

Mitigation Recommendations

A fix is available and should be applied by updating libcurl to the patched versions provided by the vendor. Ubuntu users should perform a standard system update to receive the necessary security patches. For older Ubuntu LTS releases under extended support, Ubuntu Pro provides fixes via its Legacy Support add-on. No additional mitigation steps are required beyond applying the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-9crq-qh8v-6xmm
Osv Schema Version
1.4.0
Aliases
["CVE-2026-11856"]
Cvss Version
3.1

Threat ID: 6a483cb527e9c79719d820db

Added to database: 07/03/2026, 22:50:29 UTC

Last enriched: 09/24/2026, 08:50:29 UTC

Last updated: 10/02/2026, 18:35:24 UTC

Views: 114

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses