Multiples vulnérabilités dans Curl (02 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Curl. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.
CSIRTS triage
- What
- Multiple vulnerabilities in Curl enable data confidentiality breach, data integrity breach, and security policy bypass.
- Who is affected
- Systems using vulnerable versions of Curl are affected.
- Urgency
- Moderate to high urgency due to integrity and confidentiality risks.
- Action
- Update Curl to a patched version as specified in the security advisory.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Curl
Get an email when a new Curl advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1108/
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-80255 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13608 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-82208 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-80230 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19931 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18924 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-82209 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-80229 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-80231 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-82208: wolfSSL CA-cache hit overrides callbackmsrc
- mediumCVE-2026-19931: Negotiate ambient user conn reusemsrc
- mediumCVE-2026-18924: HTTP/2 server push UAFmsrc
- lowCVE-2026-13608: OpenLDAP SASL authentication bypassmsrc
- medium[UPDATE] [mittel] cURL: Mehrere Schwachstellencert-bund
- highCVE-2026-82209: When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check…nvd
- highCVE-2026-82208: With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callbac…nvd
- highCVE-2026-80255: A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 3…nvd
- highCVE-2026-80231: A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostna…nvd
- highCVE-2026-80230: When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer veri…nvd
- highCVE-2026-80229: When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive th…nvd
- criticalCVE-2026-19931: A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using N…nvd
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans Typo3 (08 septembre 2026)2026-09-08
- unknownMultiples vulnérabilités dans les produits SAP (08 septembre 2026)2026-09-08
- unknownMultiples vulnérabilités dans Mattermost Server (08 septembre 2026)2026-09-08
- unknownVulnérabilité dans les produits Adobe (08 septembre 2026)2026-09-08
- unknownMultiples vulnérabilités dans strongSwan (08 septembre 2026)2026-09-08