curl security update (CVE-2026-11856)
cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols. Security Fix(es): Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.(CVE-2026-11856) A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.(CVE-2026-13608) A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.(CVE-2026-18924) A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.(CVE-2026-19931) When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.(CVE-2026-80230) A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.(CVE-2026-80231) When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`). Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`).(CVE-2026-82209)
AI Analysis
Technical Summary
CVE-2026-11856 describes a flaw in libcurl's handling of Digest authentication when reusing a handle for transfers to different HTTP origins. Specifically, the Authorization header meant for the first origin (hostA) is incorrectly reused and sent to a second, different origin (hostB). This behavior can cause sensitive authentication information to be exposed to unintended servers. The vulnerability affects numerous versions of curl, including but not limited to versions prior to 8.18.0-1ubuntu2.4 on Ubuntu 26.04 LTS and earlier versions on other Ubuntu LTS releases. The issue was discovered and patched, with updates provided by Ubuntu and available via standard system updates or Ubuntu Pro for extended support versions.
Potential Impact
A remote attacker could exploit this vulnerability to obtain sensitive information by tricking libcurl into sending authentication credentials intended for one host to another host. This could lead to unauthorized disclosure of credentials and potentially compromise confidentiality, integrity, and availability of communications relying on libcurl with Digest authentication.
Mitigation Recommendations
A fix is available and should be applied by updating libcurl to the patched versions provided by the vendor. Ubuntu users should perform a standard system update to receive the necessary security patches. For older Ubuntu LTS releases under extended support, Ubuntu Pro provides fixes via its Legacy Support add-on. No additional mitigation steps are required beyond applying the official patches.
curl security update (CVE-2026-11856)
Description
cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols. Security Fix(es): Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.(CVE-2026-11856) A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.(CVE-2026-13608) A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.(CVE-2026-18924) A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.(CVE-2026-19931) When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.(CVE-2026-80230) A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.(CVE-2026-80231) When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`). Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`).(CVE-2026-82209)
CVSS v3.1
Score 9.8critical
Affected software
pkg:deb/ubuntu/curl?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/curl?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/curl?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/curl?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/curl?arch=source&distro=jammypkg:deb/ubuntu/curl?arch=source&distro=noblepkg:deb/ubuntu/curl?arch=source&distro=questingpkg:deb/ubuntu/curl?arch=source&distro=resolutepkg:rpm/openEuler/curl&distro=openEuler-24.03-LTS-SP4Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-11856 describes a flaw in libcurl's handling of Digest authentication when reusing a handle for transfers to different HTTP origins. Specifically, the Authorization header meant for the first origin (hostA) is incorrectly reused and sent to a second, different origin (hostB). This behavior can cause sensitive authentication information to be exposed to unintended servers. The vulnerability affects numerous versions of curl, including but not limited to versions prior to 8.18.0-1ubuntu2.4 on Ubuntu 26.04 LTS and earlier versions on other Ubuntu LTS releases. The issue was discovered and patched, with updates provided by Ubuntu and available via standard system updates or Ubuntu Pro for extended support versions.
Potential Impact
A remote attacker could exploit this vulnerability to obtain sensitive information by tricking libcurl into sending authentication credentials intended for one host to another host. This could lead to unauthorized disclosure of credentials and potentially compromise confidentiality, integrity, and availability of communications relying on libcurl with Digest authentication.
Mitigation Recommendations
A fix is available and should be applied by updating libcurl to the patched versions provided by the vendor. Ubuntu users should perform a standard system update to receive the necessary security patches. For older Ubuntu LTS releases under extended support, Ubuntu Pro provides fixes via its Legacy Support add-on. No additional mitigation steps are required beyond applying the official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9crq-qh8v-6xmm
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-11856"]
- Cvss Version
- 3.1
Threat ID: 6a483cb527e9c79719d820db
Added to database: 07/03/2026, 22:50:29 UTC
Last enriched: 09/24/2026, 08:50:29 UTC
Last updated: 10/02/2026, 18:35:24 UTC
Views: 114
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.