Multiple vulnerabilities in cURL and libcurl (June 24, 2026)
Multiple vulnerabilities have been discovered in cURL and libcurl. Some of them allow an attacker to cause remote denial of service, a breach of data confidentiality, and a security policy bypass.
CSIRTS triage
- What
- Multiple vulnerabilities allow for denial of service, data confidentiality breaches, and security policy bypass.
- Who is affected
- Users of cURL and libcurl.
- Urgency
- Remediation is important as vulnerabilities could lead to significant security issues.
- Action
- Upgrade to the latest versions of cURL and libcurl.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch cURL and libcurl
Get an email when a new cURL and libcurl advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0797/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-89260.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-113521.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-84580.54% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-95460.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-277822.9% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 86% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-105360.89% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-89320.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-118560.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-115860.86% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-120640.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownUSN-8670-2: curl vulnerabilityubuntu
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- unknownUSN-8670-1: curl vulnerabilityubuntu
- high[UPDATE] [high] cURL: Multiple vulnerabilitiescert-bund
- unknownUSN-8651-1: curl vulnerabilityubuntu
- unknownMultiple vulnerabilities in Tenable Security Center (August 14, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 15, 2026)cert-fr-avis
- mediumCVE-2026-8458: wrong reuse for different servicesmsrc
- mediumCVE-2026-8927: env-set cross-proxy Digest auth state leakmsrc
- mediumCVE-2026-8925: SASL double-freemsrc
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21