USN-8651-1: curl vulnerability
It was discovered that curl incorrectly handled reusing connections when the origin changed between transfers. A remote attacker could possibly use this issue to obtain sensitive information.
CSIRTS triage
- What
- curl incorrectly reuses connections when origin changes between transfers, permitting information disclosure.
- Who is affected
- curl users performing sequential transfers with origin changes.
- Urgency
- Unknown; requires assessment of exploitation likelihood in typical deployment patterns.
- Action
- Update curl to patched version when available; monitor curl security advisories for CVE-2026-11856 details.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch curl
Get an email when a new curl advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8651-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-118560.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-11856 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Tenable Security Center (August 14, 2026)cert-fr-avis
- mediumCVE-2026-11856: cross-origin Digest auth state leakmsrc
- criticalCVE-2026-11856: Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest*…nvd
- unknownMultiple vulnerabilities in cURL and libcurl (June 24, 2026)cert-fr-avis
More from Ubuntu Security Notices
- unknownUSN-8563-4: nginx regression2026-08-19
- unknownUSN-8650-1: Cap'n Proto vulnerabilities2026-08-19
- unknownUSN-8649-1: libheif vulnerabilities2026-08-19
- unknownUSN-8563-3: nginx vulnerability2026-08-19
- unknownUSN-8648-1: Bind vulnerabilities2026-08-19