USN-8525-1: curl vulnerabilities
Harry Sintonen discovered that curl incorrectly handled credentials when following HTTP redirects in conjunction with .netrc files. An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2024-11053) Hiroki Kurosawa discovered that curl incorrectly handled OCSP stapling responses. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-8096) Joshua Rogers discovered that curl had a use-after-free vulnerability when resetting and cleaning up HTTP/2 stream handles. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS, Ubuntu 25.04, and Ubuntu 25.10. (CVE-2026-10536) Quac Tran and Ngoc Hieu discovered that curl incorrectly reused connections when switching authentication methods to the same host. An attacker could possibly use this issue to obtain sensitive information or perform unauthorized actions. This issue only affected Ubuntu 20.04 LTS. (CVE-2026-5545) Osama Hamad discovered that curl incorrectly reused SMB connections when the target share differed between transfers. An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-5773) Muhamad Arga Reksapati discovered that curl incorrectly forwarded Digest proxy authentication credentials to a different proxy host. An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-7168) It was discovered that curl incorrectly skipped SSH host verification options when using schemeless URLs with --proto-default. An attacker could possibly use this issue to perform machine-in-the-middle attacks. This issue only affected Ubuntu 25.04 and Ubunt
CSIRTS triage
- What
- curl has several vulnerabilities that could lead to information disclosure or denial of service.
- Who is affected
- Affected deployments include Ubuntu 14.04 LTS, 16.04 LTS, 18.04 LTS, 24.04 LTS, 25.04, and 25.10.
- Urgency
- Remediation is urgent due to the potential for sensitive information exposure and denial of service.
- Action
- Update to the latest version of curl.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch curl
Get an email when a new curl advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8525-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2024-110531.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 70% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-80960.73% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-105360.89% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-55450.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-57730.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-71680.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-120640.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-115860.86% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-113521.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-115640.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2024-11053 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-8096 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10536 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-5545 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-5773 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7168 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12064 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-11586 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-11352 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-11564 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] cURL: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Tenable Security Center (August 14, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 15, 2026)cert-fr-avis
- highCVE-2026-12064: proto-default skips SSH verificationmsrc
- mediumCVE-2026-10536: HTTP/2 stream-dependency tree UAFmsrc
- medium[UPDATE] [medium] cURL: Vulnerability allows information disclosurecert-bund
- medium[UPDATE] [medium] cURL: Vulnerability allows bypassing security measurescert-bund
- highCVE-2026-12064: When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp),…nvd
- highCVE-2026-11586: By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper …nvd
- criticalCVE-2026-11564: libcurl keeps previously used connections in a connection pool for subsequent transfers to reu…nvd
- highCVE-2026-11352: An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a rem…nvd
More from Ubuntu Security Notices
- unknownUSN-8659-4: Linux kernel (Oracle) vulnerability2026-08-26
- unknownUSN-8666-2: Linux kernel (Azure) vulnerabilities2026-08-25
- unknownUSN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities2026-08-25
- unknownUSN-8658-3: Linux kernel vulnerabilities2026-08-25
- unknownUSN-8643-4: Linux kernel vulnerabilities2026-08-25