{"cves":[{"id":"CVE-2026-6429","published":"2026-04-29T14:00:00","updated_at":"2026-05-22T18:08:06.998027+00:00","description":"\nWhen asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"Introduced-in: https://github.com/curl/curl/commit/01165e08e0d131b399fb"}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"\nAvoid using the combination netrc, HTTP and HTTP proxy.","references":["https://www.cve.org/CVERecord?id=CVE-2026-6429","https://curl.se/docs/CVE-2026-6429.html","https://ubuntu.com/security/notices/USN-8227-1"],"bugs":[""],"patches":{"curl":["upstream: https://github.com/curl/curl/commit/b4024bf808bd558026fdc6"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"bionic","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"8.20.0","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"7.81.0-1ubuntu1.24","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.5.0-2ubuntu10.9","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"8.14.1-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8.18.0-1ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8227-1"],"notices":[{"id":"USN-8227-1","title":"curl vulnerabilities","summary":"curl could be made to expose sensitive information over the network.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-04T11:40:49.935049","description":"It was discovered that curl incorrectly reused non-TLS connections when\nTLS was required in some STARTTLS configurations. A remote attacker could\npossibly use this issue to obtain sensitive information. (CVE-2026-4873)\n\nIt was discovered that curl incorrectly reused certain HTTP Negotiate\nconnections. A remote attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-5545)\n\nIt was discovered that curl incorrectly reused certain SMB connections. A\nremote attacker could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-5773)\n\nIt was discovered that curl could leak proxy credentials when handling\nredirects in some configurations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6253)\n\nIt was discovered that curl could leak cookies because of stale custom\ncookie host handling in some requests. A remote attacker could possibly\nuse this issue to obtain sensitive information. (CVE-2026-6276)\n\nIt was discovered that curl could leak .netrc credentials when reusing\nproxy connections in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6429)\n\nIt was discovered that curl could leak Digest authentication state when\nswitching proxies in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-7168)","is_hidden":false,"release_packages":{"jammy":[{"name":"curl","version":"7.81.0-1ubuntu1.24","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-gnutls","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-nss","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-doc","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-nss-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"}],"noble":[{"name":"curl","version":"8.5.0-2ubuntu10.9","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-doc","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4t64","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"}],"questing":[{"name":"curl","version":"8.14.1-2ubuntu1.3","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-doc","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4t64","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"}],"resolute":[{"name":"curl","version":"8.18.0-1ubuntu2.1","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-doc","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4t64","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-4873","CVE-2026-5773","CVE-2026-5545","CVE-2026-6429","CVE-2026-6276","CVE-2026-6253","CVE-2026-7168"]}]},{"id":"CVE-2026-6276","published":"2026-04-29T14:00:00","updated_at":"2026-05-22T18:06:04.759194+00:00","description":"\nUsing libcurl, when a custom `Host:` header is first set for an HTTP\nrequest\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nUpstream defined this as low severity."},{"author":"ebarretto","note":"Introduced-in: https://github.com/curl/curl/commit/e15e51384a423be3131"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"\nAvoid using custom `Host:` headers.","references":["https://www.cve.org/CVERecord?id=CVE-2026-6276","https://curl.se/docs/CVE-2026-6276.html","https://ubuntu.com/security/notices/USN-8227-1"],"bugs":[""],"patches":{"curl":["upstream: https://github.com/curl/curl/commit/3a19987a87f393d9394fe5ac"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"8.20.0","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"7.81.0-1ubuntu1.24","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.5.0-2ubuntu10.9","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"8.14.1-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8.18.0-1ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8227-1"],"notices":[{"id":"USN-8227-1","title":"curl vulnerabilities","summary":"curl could be made to expose sensitive information over the network.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-04T11:40:49.935049","description":"It was discovered that curl incorrectly reused non-TLS connections when\nTLS was required in some STARTTLS configurations. A remote attacker could\npossibly use this issue to obtain sensitive information. (CVE-2026-4873)\n\nIt was discovered that curl incorrectly reused certain HTTP Negotiate\nconnections. A remote attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-5545)\n\nIt was discovered that curl incorrectly reused certain SMB connections. A\nremote attacker could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-5773)\n\nIt was discovered that curl could leak proxy credentials when handling\nredirects in some configurations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6253)\n\nIt was discovered that curl could leak cookies because of stale custom\ncookie host handling in some requests. A remote attacker could possibly\nuse this issue to obtain sensitive information. (CVE-2026-6276)\n\nIt was discovered that curl could leak .netrc credentials when reusing\nproxy connections in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6429)\n\nIt was discovered that curl could leak Digest authentication state when\nswitching proxies in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-7168)","is_hidden":false,"release_packages":{"jammy":[{"name":"curl","version":"7.81.0-1ubuntu1.24","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-gnutls","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-nss","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-doc","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-nss-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"}],"noble":[{"name":"curl","version":"8.5.0-2ubuntu10.9","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-doc","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4t64","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"}],"questing":[{"name":"curl","version":"8.14.1-2ubuntu1.3","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-doc","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4t64","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"}],"resolute":[{"name":"curl","version":"8.18.0-1ubuntu2.1","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-doc","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4t64","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-4873","CVE-2026-5773","CVE-2026-5545","CVE-2026-6429","CVE-2026-6276","CVE-2026-6253","CVE-2026-7168"]}]},{"id":"CVE-2026-6253","published":"2026-04-29T14:00:00","updated_at":"2026-05-21T14:45:25.073560+00:00","description":"\ncurl might erroneously pass on credentials for a first proxy to a second\nproxy.\nThis can happen when the following conditions are true:\n1. curl is setup to use specific different proxies for different URL\nschemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to\nfollow\n a redirect to a URL using another scheme (say `https://`), accessed\nusing a\n second, different, proxy","ubuntu_description":"","notes":[{"author":"ebarretto","note":"Introduced-in: https://github.com/curl/curl/commit/3b60bb725913ce"}],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"\nAvoid using proxies with credentials.","references":["https://www.cve.org/CVERecord?id=CVE-2026-6253","https://curl.se/docs/CVE-2026-6253.html","https://ubuntu.com/security/notices/USN-8227-1"],"bugs":[""],"patches":{"curl":["upstream: https://github.com/curl/curl/commit/188c2f166a20fa97c2325"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"bionic","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"8.20.0","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"7.81.0-1ubuntu1.24","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.5.0-2ubuntu10.9","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"8.14.1-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8.18.0-1ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8227-1"],"notices":[{"id":"USN-8227-1","title":"curl vulnerabilities","summary":"curl could be made to expose sensitive information over the network.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-04T11:40:49.935049","description":"It was discovered that curl incorrectly reused non-TLS connections when\nTLS was required in some STARTTLS configurations. A remote attacker could\npossibly use this issue to obtain sensitive information. (CVE-2026-4873)\n\nIt was discovered that curl incorrectly reused certain HTTP Negotiate\nconnections. A remote attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-5545)\n\nIt was discovered that curl incorrectly reused certain SMB connections. A\nremote attacker could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-5773)\n\nIt was discovered that curl could leak proxy credentials when handling\nredirects in some configurations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6253)\n\nIt was discovered that curl could leak cookies because of stale custom\ncookie host handling in some requests. A remote attacker could possibly\nuse this issue to obtain sensitive information. (CVE-2026-6276)\n\nIt was discovered that curl could leak .netrc credentials when reusing\nproxy connections in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6429)\n\nIt was discovered that curl could leak Digest authentication state when\nswitching proxies in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-7168)","is_hidden":false,"release_packages":{"jammy":[{"name":"curl","version":"7.81.0-1ubuntu1.24","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-gnutls","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-nss","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-doc","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-nss-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"}],"noble":[{"name":"curl","version":"8.5.0-2ubuntu10.9","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-doc","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4t64","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"}],"questing":[{"name":"curl","version":"8.14.1-2ubuntu1.3","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-doc","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4t64","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"}],"resolute":[{"name":"curl","version":"8.18.0-1ubuntu2.1","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-doc","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4t64","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-4873","CVE-2026-5773","CVE-2026-5545","CVE-2026-6429","CVE-2026-6276","CVE-2026-6253","CVE-2026-7168"]}]},{"id":"CVE-2026-5773","published":"2026-04-29T14:00:00","updated_at":"2026-07-10T21:46:36.369887+00:00","description":"\nlibcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\nlibcurl features a pool of recent connections so that subsequent requests\ncan\nreuse an existing connection to avoid overhead.\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different 'share' than the new subsequent transfer\nshould.\nThis could in unlucky situations lead to the download of the wrong file or\nthe\nupload of a file to the wrong place. When this happens, the same\ncredentials\nare used and the server name is the same.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\ncurl is dropping support for SMB later in 2026 and only supports SMB version 1"},{"author":"ebarretto","note":"Introduced-in: https://github.com/curl/curl/commit/aec2e865f0"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"\nAvoid using SMB","references":["https://www.cve.org/CVERecord?id=CVE-2026-5773","https://curl.se/docs/CVE-2026-5773.html","https://ubuntu.com/security/notices/USN-8227-1","https://ubuntu.com/security/notices/USN-8525-1"],"bugs":[""],"patches":{"curl":["upstream: https://github.com/curl/curl/commit/74a169575d6412d"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"bionic","status":"released","description":"7.58.0-2ubuntu3.24+esm10","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"7.68.0-1ubuntu2.25+esm5","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"7.47.0-1ubuntu2.19+esm17","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"8.20.0","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"7.81.0-1ubuntu1.24","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.5.0-2ubuntu10.9","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"8.14.1-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8.18.0-1ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8227-1","USN-8525-1"],"notices":[{"id":"USN-8227-1","title":"curl vulnerabilities","summary":"curl could be made to expose sensitive information over the network.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-04T11:40:49.935049","description":"It was discovered that curl incorrectly reused non-TLS connections when\nTLS was required in some STARTTLS configurations. A remote attacker could\npossibly use this issue to obtain sensitive information. (CVE-2026-4873)\n\nIt was discovered that curl incorrectly reused certain HTTP Negotiate\nconnections. A remote attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-5545)\n\nIt was discovered that curl incorrectly reused certain SMB connections. A\nremote attacker could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-5773)\n\nIt was discovered that curl could leak proxy credentials when handling\nredirects in some configurations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6253)\n\nIt was discovered that curl could leak cookies because of stale custom\ncookie host handling in some requests. A remote attacker could possibly\nuse this issue to obtain sensitive information. (CVE-2026-6276)\n\nIt was discovered that curl could leak .netrc credentials when reusing\nproxy connections in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6429)\n\nIt was discovered that curl could leak Digest authentication state when\nswitching proxies in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-7168)","is_hidden":false,"release_packages":{"jammy":[{"name":"curl","version":"7.81.0-1ubuntu1.24","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-gnutls","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-nss","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-doc","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-nss-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"}],"noble":[{"name":"curl","version":"8.5.0-2ubuntu10.9","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-doc","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4t64","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"}],"questing":[{"name":"curl","version":"8.14.1-2ubuntu1.3","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-doc","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4t64","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"}],"resolute":[{"name":"curl","version":"8.18.0-1ubuntu2.1","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-doc","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4t64","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-4873","CVE-2026-5773","CVE-2026-5545","CVE-2026-6429","CVE-2026-6276","CVE-2026-6253","CVE-2026-7168"]},{"id":"USN-8525-1","title":"curl vulnerabilities","summary":"Several security issues were fixed in curl.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-09T19:14:44.553058","description":"Harry Sintonen discovered that curl incorrectly handled credentials when\nfollowing HTTP redirects in conjunction with .netrc files. An attacker\ncould possibly use this issue to obtain sensitive information. This issue\nonly affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.\n(CVE-2024-11053)\n\nHiroki Kurosawa discovered that curl incorrectly handled OCSP stapling\nresponses. A remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu\n18.04 LTS. (CVE-2024-8096)\n\nJoshua Rogers discovered that curl had a use-after-free vulnerability when\nresetting and cleaning up HTTP/2 stream handles. An attacker could possibly\nuse this issue to cause a denial of service or execute arbitrary code. This\nissue only affected Ubuntu 24.04 LTS, Ubuntu 25.04, and Ubuntu 25.10.\n(CVE-2026-10536)\n\nQuac Tran and Ngoc Hieu discovered that curl incorrectly reused connections\nwhen switching authentication methods to the same host. An attacker could\npossibly use this issue to obtain sensitive information or perform\nunauthorized actions. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2026-5545)\n\nOsama Hamad discovered that curl incorrectly reused SMB connections when\nthe target share differed between transfers. An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-5773)\n\nMuhamad Arga Reksapati discovered that curl incorrectly forwarded Digest\nproxy authentication credentials to a different proxy host. An attacker\ncould possibly use this issue to obtain sensitive information. This issue\nonly affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-7168)\n\nIt was discovered that curl incorrectly skipped SSH host verification\noptions when using schemeless URLs with --proto-default. An attacker could\npossibly use this issue to perform machine-in-the-middle attacks. This\nissue only affected Ubuntu 25.04 and Ubuntu 25.10. (CVE-2026-12064)\n\nIt was discovered that curl did not enforce an upper bound on memory\nallocated for unacknowledged WebSocket PING frames. A remote attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 25.10. (CVE-2026-11586)\n\nIt was discovered that curl could stall indefinitely when a malicious\nHTTP/3 server sent a continuous stream of empty UDP datagrams. A remote\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 25.10. (CVE-2026-11352)\n\nIt was discovered that curl could incorrectly continue trusting a native\nplatform CA store after an application switched the handle to use custom CA\nmaterial. An attacker could possibly use this issue to obtain sensitive\ninformation. This issue only affected Ubuntu 25.10. (CVE-2026-11564)","is_hidden":false,"release_packages":{"bionic":[{"name":"curl","version":"7.58.0-2ubuntu3.24+esm10","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl3-gnutls","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl3-nss","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-doc","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-gnutls-dev","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-nss-dev","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-openssl-dev","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"curl","version":"7.68.0-1ubuntu2.25+esm5","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl3-gnutls","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl3-nss","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-doc","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-gnutls-dev","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-nss-dev","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-openssl-dev","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"}],"noble":[{"name":"curl","version":"8.5.0-2ubuntu10.11","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl4-doc","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl4t64","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"}],"questing":[{"name":"curl","version":"8.14.1-2ubuntu1.5","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl4-doc","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl4t64","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"}],"resolute":[{"name":"curl","version":"8.18.0-1ubuntu2.3","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-doc","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4t64","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"}],"trusty":[{"name":"curl","version":"7.35.0-1ubuntu2.20+esm21","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3-gnutls","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3-nss","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-doc","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-gnutls-dev","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-nss-dev","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-openssl-dev","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"curl","version":"7.47.0-1ubuntu2.19+esm17","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3-gnutls","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3-nss","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-doc","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-gnutls-dev","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-nss-dev","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-openssl-dev","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-11352","CVE-2026-7168","CVE-2024-8096","CVE-2026-5773","CVE-2026-10536","CVE-2026-5545","CVE-2026-11564","CVE-2026-11586","CVE-2024-11053","CVE-2026-12064"]}]},{"id":"CVE-2026-5545","published":"2026-04-29T14:00:00","updated_at":"2026-07-10T21:46:36.369887+00:00","description":"\nlibcurl might in some circumstances reuse the wrong connection when asked\nto\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one,\nwhen\nboth use the same host.\nlibcurl features a pool of recent connections so that subsequent requests\ncan\nreuse an existing connection to avoid overhead.\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in\nfact\nstill using the connection authenticated for user1...","ubuntu_description":"","notes":[{"author":"ebarretto","note":"Introduced-in: https://github.com/curl/curl/commit/e56ae1426c"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"\nAvoid using HTTP Negotiate in your application","references":["https://www.cve.org/CVERecord?id=CVE-2026-5545","https://curl.se/docs/CVE-2026-5545.html","https://ubuntu.com/security/notices/USN-8227-1","https://ubuntu.com/security/notices/USN-8525-1"],"bugs":[""],"patches":{"curl":["upstream: https://github.com/curl/curl/commit/33e43985b8f3b9e6669"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"7.68.0-1ubuntu2.25+esm5","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"pending","description":"8.20.0","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"7.81.0-1ubuntu1.24","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.5.0-2ubuntu10.9","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"8.14.1-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8.18.0-1ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8227-1","USN-8525-1"],"notices":[{"id":"USN-8227-1","title":"curl vulnerabilities","summary":"curl could be made to expose sensitive information over the network.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-04T11:40:49.935049","description":"It was discovered that curl incorrectly reused non-TLS connections when\nTLS was required in some STARTTLS configurations. A remote attacker could\npossibly use this issue to obtain sensitive information. (CVE-2026-4873)\n\nIt was discovered that curl incorrectly reused certain HTTP Negotiate\nconnections. A remote attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-5545)\n\nIt was discovered that curl incorrectly reused certain SMB connections. A\nremote attacker could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-5773)\n\nIt was discovered that curl could leak proxy credentials when handling\nredirects in some configurations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6253)\n\nIt was discovered that curl could leak cookies because of stale custom\ncookie host handling in some requests. A remote attacker could possibly\nuse this issue to obtain sensitive information. (CVE-2026-6276)\n\nIt was discovered that curl could leak .netrc credentials when reusing\nproxy connections in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6429)\n\nIt was discovered that curl could leak Digest authentication state when\nswitching proxies in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-7168)","is_hidden":false,"release_packages":{"jammy":[{"name":"curl","version":"7.81.0-1ubuntu1.24","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-gnutls","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-nss","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-doc","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-nss-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"}],"noble":[{"name":"curl","version":"8.5.0-2ubuntu10.9","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-doc","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4t64","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"}],"questing":[{"name":"curl","version":"8.14.1-2ubuntu1.3","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-doc","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4t64","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"}],"resolute":[{"name":"curl","version":"8.18.0-1ubuntu2.1","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-doc","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4t64","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-4873","CVE-2026-5773","CVE-2026-5545","CVE-2026-6429","CVE-2026-6276","CVE-2026-6253","CVE-2026-7168"]},{"id":"USN-8525-1","title":"curl vulnerabilities","summary":"Several security issues were fixed in curl.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-09T19:14:44.553058","description":"Harry Sintonen discovered that curl incorrectly handled credentials when\nfollowing HTTP redirects in conjunction with .netrc files. An attacker\ncould possibly use this issue to obtain sensitive information. This issue\nonly affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.\n(CVE-2024-11053)\n\nHiroki Kurosawa discovered that curl incorrectly handled OCSP stapling\nresponses. A remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu\n18.04 LTS. (CVE-2024-8096)\n\nJoshua Rogers discovered that curl had a use-after-free vulnerability when\nresetting and cleaning up HTTP/2 stream handles. An attacker could possibly\nuse this issue to cause a denial of service or execute arbitrary code. This\nissue only affected Ubuntu 24.04 LTS, Ubuntu 25.04, and Ubuntu 25.10.\n(CVE-2026-10536)\n\nQuac Tran and Ngoc Hieu discovered that curl incorrectly reused connections\nwhen switching authentication methods to the same host. An attacker could\npossibly use this issue to obtain sensitive information or perform\nunauthorized actions. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2026-5545)\n\nOsama Hamad discovered that curl incorrectly reused SMB connections when\nthe target share differed between transfers. An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-5773)\n\nMuhamad Arga Reksapati discovered that curl incorrectly forwarded Digest\nproxy authentication credentials to a different proxy host. An attacker\ncould possibly use this issue to obtain sensitive information. This issue\nonly affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-7168)\n\nIt was discovered that curl incorrectly skipped SSH host verification\noptions when using schemeless URLs with --proto-default. An attacker could\npossibly use this issue to perform machine-in-the-middle attacks. This\nissue only affected Ubuntu 25.04 and Ubuntu 25.10. (CVE-2026-12064)\n\nIt was discovered that curl did not enforce an upper bound on memory\nallocated for unacknowledged WebSocket PING frames. A remote attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 25.10. (CVE-2026-11586)\n\nIt was discovered that curl could stall indefinitely when a malicious\nHTTP/3 server sent a continuous stream of empty UDP datagrams. A remote\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 25.10. (CVE-2026-11352)\n\nIt was discovered that curl could incorrectly continue trusting a native\nplatform CA store after an application switched the handle to use custom CA\nmaterial. An attacker could possibly use this issue to obtain sensitive\ninformation. This issue only affected Ubuntu 25.10. (CVE-2026-11564)","is_hidden":false,"release_packages":{"bionic":[{"name":"curl","version":"7.58.0-2ubuntu3.24+esm10","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl3-gnutls","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl3-nss","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-doc","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-gnutls-dev","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-nss-dev","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-openssl-dev","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"curl","version":"7.68.0-1ubuntu2.25+esm5","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl3-gnutls","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl3-nss","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-doc","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-gnutls-dev","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-nss-dev","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-openssl-dev","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"}],"noble":[{"name":"curl","version":"8.5.0-2ubuntu10.11","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl4-doc","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl4t64","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"}],"questing":[{"name":"curl","version":"8.14.1-2ubuntu1.5","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl4-doc","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl4t64","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"}],"resolute":[{"name":"curl","version":"8.18.0-1ubuntu2.3","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-doc","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4t64","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"}],"trusty":[{"name":"curl","version":"7.35.0-1ubuntu2.20+esm21","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3-gnutls","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3-nss","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-doc","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-gnutls-dev","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-nss-dev","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-openssl-dev","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"curl","version":"7.47.0-1ubuntu2.19+esm17","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3-gnutls","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3-nss","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-doc","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-gnutls-dev","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-nss-dev","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-openssl-dev","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-11352","CVE-2026-7168","CVE-2024-8096","CVE-2026-5773","CVE-2026-10536","CVE-2026-5545","CVE-2026-11564","CVE-2026-11586","CVE-2024-11053","CVE-2026-12064"]}]},{"id":"CVE-2026-4873","published":"2026-04-29T14:00:00","updated_at":"2026-05-22T18:07:06.047240+00:00","description":"\nA vulnerability exists where a connection requiring TLS incorrectly reuses\nan\nexisting unencrypted connection from the same connection pool. If an\ninitial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent\nrequest\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nThis flaw requires a rather special series of events to trigger. Such a series is unlikely to be used much in the wild."},{"author":"ebarretto","note":"Introduced-in: https://github.com/curl/curl/commit/ec3bb8f727405642a"}],"codename":null,"priority":"low","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4873","https://curl.se/docs/CVE-2026-4873.html","https://ubuntu.com/security/notices/USN-8227-1"],"bugs":[""],"patches":{"curl":["upstream: https://github.com/curl/curl/commit/507e7be573b0a76fca597b75"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"bionic","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"8.20.0","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"7.81.0-1ubuntu1.24","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.5.0-2ubuntu10.9","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"8.14.1-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8.18.0-1ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8227-1"],"notices":[{"id":"USN-8227-1","title":"curl vulnerabilities","summary":"curl could be made to expose sensitive information over the network.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-04T11:40:49.935049","description":"It was discovered that curl incorrectly reused non-TLS connections when\nTLS was required in some STARTTLS configurations. A remote attacker could\npossibly use this issue to obtain sensitive information. (CVE-2026-4873)\n\nIt was discovered that curl incorrectly reused certain HTTP Negotiate\nconnections. A remote attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-5545)\n\nIt was discovered that curl incorrectly reused certain SMB connections. A\nremote attacker could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-5773)\n\nIt was discovered that curl could leak proxy credentials when handling\nredirects in some configurations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6253)\n\nIt was discovered that curl could leak cookies because of stale custom\ncookie host handling in some requests. A remote attacker could possibly\nuse this issue to obtain sensitive information. (CVE-2026-6276)\n\nIt was discovered that curl could leak .netrc credentials when reusing\nproxy connections in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6429)\n\nIt was discovered that curl could leak Digest authentication state when\nswitching proxies in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-7168)","is_hidden":false,"release_packages":{"jammy":[{"name":"curl","version":"7.81.0-1ubuntu1.24","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-gnutls","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-nss","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-doc","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-nss-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"}],"noble":[{"name":"curl","version":"8.5.0-2ubuntu10.9","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-doc","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4t64","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"}],"questing":[{"name":"curl","version":"8.14.1-2ubuntu1.3","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-doc","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4t64","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"}],"resolute":[{"name":"curl","version":"8.18.0-1ubuntu2.1","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-doc","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4t64","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-4873","CVE-2026-5773","CVE-2026-5545","CVE-2026-6429","CVE-2026-6276","CVE-2026-6253","CVE-2026-7168"]}]},{"id":"CVE-2026-22741","published":"2026-04-29T12:16:00","updated_at":"2026-05-14T11:33:02.958654+00:00","description":"\nSpring MVC and WebFlux applications are vulnerable to cache poisoning when\nresolving static resources.\nMore precisely, an application can be vulnerable when all the following are\ntrue:\n * the application is using Spring MVC or Spring WebFlux\n * the application is configuring the  resource chain support\nhttps://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title\n with caching enabled\n * the application adds support for encoded resources resolution\n * the resource cache must be empty when the attacker has access to the\napplication\nWhen all the conditions above are met, the attacker can send malicious\nrequests and poison the resource cache with resources using the wrong\nencoding. This can cause a denial of service by breaking the front-end\napplication for clients.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-22741","https://spring.io/security/cve-2026-22741"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-22740","published":"2026-04-29T12:16:00","updated_at":"2026-05-13T16:48:20.356935+00:00","description":"\nA WebFlux server application that processes multipart requests creates temp\nfiles for parts larger than 10 K. Under some circumstances, temp files may\nremain not deleted after the request is fully processed. This allows an\nattacker to consume available disk space.\nOlder, unsupported versions are also affected.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-22740","https://spring.io/security/cve-2026-22740"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40687","published":"2026-04-29T12:00:00","updated_at":"2026-06-26T07:55:43.614959+00:00","description":"\nIn Exim before 4.99.2, when the SPA authentication driver is used with an\nadversarial SPA resource, there can be an out-of-bounds write that crashes\nthe connection instance, or erroneous data processing that divulges data\nfrom uninitialized heap memory.","ubuntu_description":"","notes":[{"author":"mrmajumder","note":"Bionic and below require f3ebb786e451da973560f1c9d8cdb151d25108b5\nwhich introduces over 3000 LoC"}],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40687","https://lists.exim.org/lurker/message/20260429.121733.f58d9686.en.html","https://ubuntu.com/security/notices/USN-8228-1","https://ubuntu.com/security/notices/USN-8382-1"],"bugs":[""],"patches":{"exim4":["upstream: https://code.exim.org/exim/exim/commit/ecf4e26eea8135c39cd6ee61d92dbcb1d759546d"]},"tags":{},"packages":[{"name":"exim4","source":"https://ubuntu.com/security/cve?package=exim4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exim4","debian":"https://tracker.debian.org/pkg/exim4","statuses":[{"release_codename":"upstream","status":"released","description":"4.99.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4.93-13ubuntu1.12+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"4.95-4ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"4.97-4ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"4.98.2-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"4.99.1-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-8228-1","USN-8382-1"],"notices":[{"id":"USN-8228-1","title":"Exim vulnerabilities","summary":"Several security issues were fixed in Exim.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-04T11:50:57.644252","description":"It was discovered that Exim incorrectly handled parsing malformed JSON\nin message headers. A remote attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2026-40685)\n\nIt was discovered that Exim incorrectly handled processing of UTF-8\ntrailing characters. A remote attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-40686)\n\nIt was discovered that Exim incorrectly handled SPA authenticator input.\nAn authenticated user could possibly use this issue to execute arbitrary\ncode. (CVE-2026-40687)","is_hidden":false,"release_packages":{"jammy":[{"name":"exim4","version":"4.95-4ubuntu2.7","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-base","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-config","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-daemon-heavy","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-daemon-light","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-dev","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"eximon4","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"}],"noble":[{"name":"exim4","version":"4.97-4ubuntu4.4","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-base","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-config","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-daemon-heavy","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-daemon-light","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-dev","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"eximon4","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"}],"questing":[{"name":"exim4","version":"4.98.2-1ubuntu2.1","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-base","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-config","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-daemon-heavy","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-daemon-light","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-dev","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"eximon4","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"}],"resolute":[{"name":"exim4","version":"4.99.1-1ubuntu1.1","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-base","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-config","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-daemon-heavy","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-daemon-light","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-dev","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"eximon4","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-40685","CVE-2026-40687","CVE-2026-40686"]},{"id":"USN-8382-1","title":"Exim vulnerabilities","summary":"Several security issues were fixed in Exim.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-03T16:29:23.736580","description":"Timo Longin discovered that Exim incorrectly handled certain SMTP messages\nin PIPELINING/CHUNKING configurations. A remote attacker could possibly use\nthis issue to perform SMTP smuggling. This issue only affected Ubuntu\n14.04 LTS. (CVE-2023-51766)\n\nIt was discovered that Exim incorrectly handled certain malformed JSON\ndata in headers. A remote attacker could possibly use this issue to crash\nExim, resulting in a denial of service, or execute arbitrary code. This\nissue only affected Ubuntu 20.04 LTS. (CVE-2026-40685)\n\nIt was discovered that Exim incorrectly handled certain malformed UTF-8\nheaders. A remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2026-40686)\n\nIt was discovered that Exim incorrectly handled certain SPA resources.\nA remote attacker could possibly use this issue to crash Exim, resulting in\na denial of service, or obtain sensitive information. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2026-40687)\n\nIt was discovered that Exim incorrectly handled certain CHUNKING\ntransfers in some GnuTLS configurations. A remote attacker could possibly\nuse this issue to crash Exim, resulting in a denial of service, or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS. (CVE-2026-45185)\n\nWarisjeet Singh discovered that Exim incorrectly handled certain proxy\nconnections in builds with proxy support enabled. A remote attacker could\npossibly use this issue to obtain sensitive information. This issue only\naffected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.\n(CVE-2026-48840)","is_hidden":false,"release_packages":{"bionic":[{"name":"exim4","version":"4.90.1-1ubuntu1.10+esm6","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-base","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-config","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-daemon-heavy","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-daemon-light","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-dev","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"eximon4","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"exim4","version":"4.93-13ubuntu1.12+esm1","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-base","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-config","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-daemon-heavy","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-daemon-light","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-dev","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"eximon4","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"exim4","version":"4.82-3ubuntu2.4+esm9","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-base","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-config","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-daemon-heavy","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-daemon-light","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-dev","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"eximon4","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"exim4","version":"4.86.2-2ubuntu2.6+esm9","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-base","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-config","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-daemon-heavy","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-daemon-light","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-dev","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"eximon4","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-40687","CVE-2026-45185","CVE-2026-40685","CVE-2026-40686","CVE-2023-51766","CVE-2026-48840"]}]},{"id":"CVE-2026-40686","published":"2026-04-29T12:00:00","updated_at":"2026-06-06T00:24:35.825690+00:00","description":"\nIn Exim before 4.99.2, when utf8 operators are enabled, there is an\nout-of-bounds read if large UTF-8 trailing characters are present\n(malformed UTF-8 header data). Information might be divulged within an\nerror message produced during handling of an unrelated e-mail message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40686","https://lists.exim.org/lurker/message/20260429.121733.f58d9686.en.html","https://ubuntu.com/security/notices/USN-8228-1","https://ubuntu.com/security/notices/USN-8382-1"],"bugs":[""],"patches":{"exim4":["upstream: https://code.exim.org/exim/exim/commit/ecf4e26eea8135c39cd6ee61d92dbcb1d759546d"]},"tags":{},"packages":[{"name":"exim4","source":"https://ubuntu.com/security/cve?package=exim4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exim4","debian":"https://tracker.debian.org/pkg/exim4","statuses":[{"release_codename":"upstream","status":"released","description":"4.99.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4.93-13ubuntu1.12+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"4.95-4ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"4.97-4ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"4.98.2-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"4.99.1-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-8228-1","USN-8382-1"],"notices":[{"id":"USN-8228-1","title":"Exim vulnerabilities","summary":"Several security issues were fixed in Exim.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-04T11:50:57.644252","description":"It was discovered that Exim incorrectly handled parsing malformed JSON\nin message headers. A remote attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2026-40685)\n\nIt was discovered that Exim incorrectly handled processing of UTF-8\ntrailing characters. A remote attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-40686)\n\nIt was discovered that Exim incorrectly handled SPA authenticator input.\nAn authenticated user could possibly use this issue to execute arbitrary\ncode. (CVE-2026-40687)","is_hidden":false,"release_packages":{"jammy":[{"name":"exim4","version":"4.95-4ubuntu2.7","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-base","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-config","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-daemon-heavy","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-daemon-light","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-dev","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"eximon4","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"}],"noble":[{"name":"exim4","version":"4.97-4ubuntu4.4","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-base","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-config","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-daemon-heavy","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-daemon-light","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-dev","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"eximon4","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"}],"questing":[{"name":"exim4","version":"4.98.2-1ubuntu2.1","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-base","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-config","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-daemon-heavy","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-daemon-light","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-dev","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"eximon4","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"}],"resolute":[{"name":"exim4","version":"4.99.1-1ubuntu1.1","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-base","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-config","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-daemon-heavy","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-daemon-light","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-dev","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"eximon4","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-40685","CVE-2026-40687","CVE-2026-40686"]},{"id":"USN-8382-1","title":"Exim vulnerabilities","summary":"Several security issues were fixed in Exim.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-03T16:29:23.736580","description":"Timo Longin discovered that Exim incorrectly handled certain SMTP messages\nin PIPELINING/CHUNKING configurations. A remote attacker could possibly use\nthis issue to perform SMTP smuggling. This issue only affected Ubuntu\n14.04 LTS. (CVE-2023-51766)\n\nIt was discovered that Exim incorrectly handled certain malformed JSON\ndata in headers. A remote attacker could possibly use this issue to crash\nExim, resulting in a denial of service, or execute arbitrary code. This\nissue only affected Ubuntu 20.04 LTS. (CVE-2026-40685)\n\nIt was discovered that Exim incorrectly handled certain malformed UTF-8\nheaders. A remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2026-40686)\n\nIt was discovered that Exim incorrectly handled certain SPA resources.\nA remote attacker could possibly use this issue to crash Exim, resulting in\na denial of service, or obtain sensitive information. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2026-40687)\n\nIt was discovered that Exim incorrectly handled certain CHUNKING\ntransfers in some GnuTLS configurations. A remote attacker could possibly\nuse this issue to crash Exim, resulting in a denial of service, or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS. (CVE-2026-45185)\n\nWarisjeet Singh discovered that Exim incorrectly handled certain proxy\nconnections in builds with proxy support enabled. A remote attacker could\npossibly use this issue to obtain sensitive information. This issue only\naffected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.\n(CVE-2026-48840)","is_hidden":false,"release_packages":{"bionic":[{"name":"exim4","version":"4.90.1-1ubuntu1.10+esm6","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-base","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-config","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-daemon-heavy","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-daemon-light","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-dev","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"eximon4","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"exim4","version":"4.93-13ubuntu1.12+esm1","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-base","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-config","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-daemon-heavy","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-daemon-light","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-dev","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"eximon4","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"exim4","version":"4.82-3ubuntu2.4+esm9","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-base","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-config","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-daemon-heavy","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-daemon-light","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-dev","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"eximon4","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"exim4","version":"4.86.2-2ubuntu2.6+esm9","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-base","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-config","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-daemon-heavy","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-daemon-light","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-dev","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"eximon4","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-40687","CVE-2026-45185","CVE-2026-40685","CVE-2026-40686","CVE-2023-51766","CVE-2026-48840"]}]},{"id":"CVE-2026-40685","published":"2026-04-29T12:00:00","updated_at":"2026-06-06T00:24:35.825690+00:00","description":"\nIn Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap\nwrite can occur when a JSON operator encounters malformed JSON in an\nuntrusted header, because of an incorrect implementation of \\ skipping.","ubuntu_description":"","notes":[{"author":"kkernick","note":"Bionic and below require f3ebb786e451da973560f1c9d8cdb151d25108b5\nwhich introduces over 3000 LoC"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40685","https://lists.exim.org/lurker/message/20260429.121733.f58d9686.en.html","https://ubuntu.com/security/notices/USN-8228-1","https://ubuntu.com/security/notices/USN-8382-1"],"bugs":[""],"patches":{"exim4":["upstream: https://code.exim.org/exim/exim/commit/ecf4e26eea8135c39cd6ee61d92dbcb1d759546d"]},"tags":{},"packages":[{"name":"exim4","source":"https://ubuntu.com/security/cve?package=exim4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exim4","debian":"https://tracker.debian.org/pkg/exim4","statuses":[{"release_codename":"upstream","status":"released","description":"4.99.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"4.95-4ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"4.97-4ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"4.98.2-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"4.99.1-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4.93-13ubuntu1.12+esm1","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-8228-1","USN-8382-1"],"notices":[{"id":"USN-8228-1","title":"Exim vulnerabilities","summary":"Several security issues were fixed in Exim.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-04T11:50:57.644252","description":"It was discovered that Exim incorrectly handled parsing malformed JSON\nin message headers. A remote attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2026-40685)\n\nIt was discovered that Exim incorrectly handled processing of UTF-8\ntrailing characters. A remote attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-40686)\n\nIt was discovered that Exim incorrectly handled SPA authenticator input.\nAn authenticated user could possibly use this issue to execute arbitrary\ncode. (CVE-2026-40687)","is_hidden":false,"release_packages":{"jammy":[{"name":"exim4","version":"4.95-4ubuntu2.7","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-base","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-config","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-daemon-heavy","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-daemon-light","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"exim4-dev","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"},{"name":"eximon4","version":"4.95-4ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7","pocket":"security"}],"noble":[{"name":"exim4","version":"4.97-4ubuntu4.4","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-base","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-config","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-daemon-heavy","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-daemon-light","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"exim4-dev","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"},{"name":"eximon4","version":"4.97-4ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4","pocket":"security"}],"questing":[{"name":"exim4","version":"4.98.2-1ubuntu2.1","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-base","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-config","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-daemon-heavy","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-daemon-light","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"exim4-dev","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"},{"name":"eximon4","version":"4.98.2-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1","pocket":"security"}],"resolute":[{"name":"exim4","version":"4.99.1-1ubuntu1.1","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-base","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-config","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-daemon-heavy","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-daemon-light","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"exim4-dev","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"},{"name":"eximon4","version":"4.99.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":"https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-40685","CVE-2026-40687","CVE-2026-40686"]},{"id":"USN-8382-1","title":"Exim vulnerabilities","summary":"Several security issues were fixed in Exim.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-03T16:29:23.736580","description":"Timo Longin discovered that Exim incorrectly handled certain SMTP messages\nin PIPELINING/CHUNKING configurations. A remote attacker could possibly use\nthis issue to perform SMTP smuggling. This issue only affected Ubuntu\n14.04 LTS. (CVE-2023-51766)\n\nIt was discovered that Exim incorrectly handled certain malformed JSON\ndata in headers. A remote attacker could possibly use this issue to crash\nExim, resulting in a denial of service, or execute arbitrary code. This\nissue only affected Ubuntu 20.04 LTS. (CVE-2026-40685)\n\nIt was discovered that Exim incorrectly handled certain malformed UTF-8\nheaders. A remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2026-40686)\n\nIt was discovered that Exim incorrectly handled certain SPA resources.\nA remote attacker could possibly use this issue to crash Exim, resulting in\na denial of service, or obtain sensitive information. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2026-40687)\n\nIt was discovered that Exim incorrectly handled certain CHUNKING\ntransfers in some GnuTLS configurations. A remote attacker could possibly\nuse this issue to crash Exim, resulting in a denial of service, or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS. (CVE-2026-45185)\n\nWarisjeet Singh discovered that Exim incorrectly handled certain proxy\nconnections in builds with proxy support enabled. A remote attacker could\npossibly use this issue to obtain sensitive information. This issue only\naffected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.\n(CVE-2026-48840)","is_hidden":false,"release_packages":{"bionic":[{"name":"exim4","version":"4.90.1-1ubuntu1.10+esm6","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-base","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-config","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-daemon-heavy","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-daemon-light","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-dev","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"eximon4","version":"4.90.1-1ubuntu1.10+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"exim4","version":"4.93-13ubuntu1.12+esm1","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-base","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-config","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-daemon-heavy","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-daemon-light","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"exim4-dev","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"},{"name":"eximon4","version":"4.93-13ubuntu1.12+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"exim4","version":"4.82-3ubuntu2.4+esm9","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-base","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-config","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-daemon-heavy","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-daemon-light","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-dev","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"eximon4","version":"4.82-3ubuntu2.4+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"exim4","version":"4.86.2-2ubuntu2.6+esm9","description":"Exim is a mail transport agent","is_source":true},{"name":"exim4","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-base","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-config","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-daemon-heavy","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-daemon-light","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"exim4-dev","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"},{"name":"eximon4","version":"4.86.2-2ubuntu2.6+esm9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exim4","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-40687","CVE-2026-45185","CVE-2026-40685","CVE-2026-40686","CVE-2023-51766","CVE-2026-48840"]}]},{"id":"CVE-2026-40684","published":"2026-04-29T12:00:00","updated_at":"2026-05-13T17:09:36.993211+00:00","description":"\nIn Exim before 4.99.2, on systems using musl libc (not glibc), an attacker\ncan crash the connection instance when malformed DNS data is present in PTR\nrecords. This is caused by a dn_expand oddity in octal printing.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is only an issue on musl libc, not glibc"}],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40684","https://lists.exim.org/lurker/message/20260429.121733.f58d9686.en.html"],"bugs":[""],"patches":{"exim4":["upstream: https://code.exim.org/exim/exim/commit/ecf4e26eea8135c39cd6ee61d92dbcb1d759546d"]},"tags":{},"packages":[{"name":"exim4","source":"https://ubuntu.com/security/cve?package=exim4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exim4","debian":"https://tracker.debian.org/pkg/exim4","statuses":[{"release_codename":"trusty","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.99.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-7168","published":"2026-04-29T00:00:00","updated_at":"2026-07-10T21:46:36.369887+00:00","description":"\nSuccessfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host\nto\na second one (`proxyB`) for a second transfer, reusing the same handle,\nmakes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"does not affect the curl command line tool"}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7168","https://ubuntu.com/security/notices/USN-8227-1","https://ubuntu.com/security/notices/USN-8525-1"],"bugs":[""],"patches":{"curl":["upstream: https://github.com/curl/curl/commit/c1cfdf59acbaf9504c45"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"bionic","status":"released","description":"7.58.0-2ubuntu3.24+esm10","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"7.68.0-1ubuntu2.25+esm5","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"7.81.0-1ubuntu1.24","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.5.0-2ubuntu10.9","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"8.14.1-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8.18.0-1ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8227-1","USN-8525-1"],"notices":[{"id":"USN-8227-1","title":"curl vulnerabilities","summary":"curl could be made to expose sensitive information over the network.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-04T11:40:49.935049","description":"It was discovered that curl incorrectly reused non-TLS connections when\nTLS was required in some STARTTLS configurations. A remote attacker could\npossibly use this issue to obtain sensitive information. (CVE-2026-4873)\n\nIt was discovered that curl incorrectly reused certain HTTP Negotiate\nconnections. A remote attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-5545)\n\nIt was discovered that curl incorrectly reused certain SMB connections. A\nremote attacker could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-5773)\n\nIt was discovered that curl could leak proxy credentials when handling\nredirects in some configurations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6253)\n\nIt was discovered that curl could leak cookies because of stale custom\ncookie host handling in some requests. A remote attacker could possibly\nuse this issue to obtain sensitive information. (CVE-2026-6276)\n\nIt was discovered that curl could leak .netrc credentials when reusing\nproxy connections in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-6429)\n\nIt was discovered that curl could leak Digest authentication state when\nswitching proxies in some situations. A remote attacker could possibly use\nthis issue to obtain sensitive information. (CVE-2026-7168)","is_hidden":false,"release_packages":{"jammy":[{"name":"curl","version":"7.81.0-1ubuntu1.24","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-gnutls","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl3-nss","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-doc","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-nss-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"7.81.0-1ubuntu1.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24","pocket":"security"}],"noble":[{"name":"curl","version":"8.5.0-2ubuntu10.9","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-doc","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"},{"name":"libcurl4t64","version":"8.5.0-2ubuntu10.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9","pocket":"security"}],"questing":[{"name":"curl","version":"8.14.1-2ubuntu1.3","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-doc","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"},{"name":"libcurl4t64","version":"8.14.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3","pocket":"security"}],"resolute":[{"name":"curl","version":"8.18.0-1ubuntu2.1","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-doc","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"},{"name":"libcurl4t64","version":"8.18.0-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-4873","CVE-2026-5773","CVE-2026-5545","CVE-2026-6429","CVE-2026-6276","CVE-2026-6253","CVE-2026-7168"]},{"id":"USN-8525-1","title":"curl vulnerabilities","summary":"Several security issues were fixed in curl.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-09T19:14:44.553058","description":"Harry Sintonen discovered that curl incorrectly handled credentials when\nfollowing HTTP redirects in conjunction with .netrc files. An attacker\ncould possibly use this issue to obtain sensitive information. This issue\nonly affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.\n(CVE-2024-11053)\n\nHiroki Kurosawa discovered that curl incorrectly handled OCSP stapling\nresponses. A remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu\n18.04 LTS. (CVE-2024-8096)\n\nJoshua Rogers discovered that curl had a use-after-free vulnerability when\nresetting and cleaning up HTTP/2 stream handles. An attacker could possibly\nuse this issue to cause a denial of service or execute arbitrary code. This\nissue only affected Ubuntu 24.04 LTS, Ubuntu 25.04, and Ubuntu 25.10.\n(CVE-2026-10536)\n\nQuac Tran and Ngoc Hieu discovered that curl incorrectly reused connections\nwhen switching authentication methods to the same host. An attacker could\npossibly use this issue to obtain sensitive information or perform\nunauthorized actions. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2026-5545)\n\nOsama Hamad discovered that curl incorrectly reused SMB connections when\nthe target share differed between transfers. An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-5773)\n\nMuhamad Arga Reksapati discovered that curl incorrectly forwarded Digest\nproxy authentication credentials to a different proxy host. An attacker\ncould possibly use this issue to obtain sensitive information. This issue\nonly affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-7168)\n\nIt was discovered that curl incorrectly skipped SSH host verification\noptions when using schemeless URLs with --proto-default. An attacker could\npossibly use this issue to perform machine-in-the-middle attacks. This\nissue only affected Ubuntu 25.04 and Ubuntu 25.10. (CVE-2026-12064)\n\nIt was discovered that curl did not enforce an upper bound on memory\nallocated for unacknowledged WebSocket PING frames. A remote attacker could\npossibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 25.10. (CVE-2026-11586)\n\nIt was discovered that curl could stall indefinitely when a malicious\nHTTP/3 server sent a continuous stream of empty UDP datagrams. A remote\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 25.10. (CVE-2026-11352)\n\nIt was discovered that curl could incorrectly continue trusting a native\nplatform CA store after an application switched the handle to use custom CA\nmaterial. An attacker could possibly use this issue to obtain sensitive\ninformation. This issue only affected Ubuntu 25.10. (CVE-2026-11564)","is_hidden":false,"release_packages":{"bionic":[{"name":"curl","version":"7.58.0-2ubuntu3.24+esm10","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl3-gnutls","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl3-nss","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-doc","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-gnutls-dev","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-nss-dev","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-openssl-dev","version":"7.58.0-2ubuntu3.24+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"curl","version":"7.68.0-1ubuntu2.25+esm5","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl3-gnutls","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl3-nss","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-doc","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-gnutls-dev","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-nss-dev","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"},{"name":"libcurl4-openssl-dev","version":"7.68.0-1ubuntu2.25+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra"}],"noble":[{"name":"curl","version":"8.5.0-2ubuntu10.11","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl4-doc","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"},{"name":"libcurl4t64","version":"8.5.0-2ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.11","pocket":"security"}],"questing":[{"name":"curl","version":"8.14.1-2ubuntu1.5","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl4-doc","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"},{"name":"libcurl4t64","version":"8.14.1-2ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.5","pocket":"security"}],"resolute":[{"name":"curl","version":"8.18.0-1ubuntu2.3","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl3t64-gnutls","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-doc","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4t64","version":"8.18.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.3","pocket":"security"}],"trusty":[{"name":"curl","version":"7.35.0-1ubuntu2.20+esm21","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3-gnutls","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3-nss","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-doc","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-gnutls-dev","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-nss-dev","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-openssl-dev","version":"7.35.0-1ubuntu2.20+esm21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"curl","version":"7.47.0-1ubuntu2.19+esm17","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3-gnutls","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl3-nss","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-doc","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-gnutls-dev","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-nss-dev","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libcurl4-openssl-dev","version":"7.47.0-1ubuntu2.19+esm17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-11352","CVE-2026-7168","CVE-2024-8096","CVE-2026-5773","CVE-2026-10536","CVE-2026-5545","CVE-2026-11564","CVE-2026-11586","CVE-2024-11053","CVE-2026-12064"]}]},{"id":"CVE-2026-7111","published":"2026-04-29T00:00:00","updated_at":"2026-05-13T16:46:54.664510+00:00","description":"\nText::CSV_XS versions before 1.62 for Perl have a use-after-free when\nregistered callbacks extend the Perl argument stack, which may enable type\nconfusion or memory corruption.\nThe Parse, print, getline, and getline_all methods invoke registered\ncallbacks (for example after_parse, before_print, or on_error) and cache\nthe Perl argument stack pointer across the call. If a callback extends the\nargument stack enough to trigger a reallocation, the return value is\nwritten through the stale pointer into the freed buffer, and the caller\nreads the original $self argument as the return value instead.\nCalling code that expects parsed data from getline_all receives the\nText::CSV_XS object in its place, leading to logic errors or crashes.\nText::CSV_XS objects used without any registered callbacks are not\naffected.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7111","https://lists.security.metacpan.org/cve-announce/msg/39453344/"],"bugs":[""],"patches":{"libtext-csv-xs-perl":[]},"tags":{},"packages":[{"name":"libtext-csv-xs-perl","source":"https://ubuntu.com/security/cve?package=libtext-csv-xs-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libtext-csv-xs-perl","debian":"https://tracker.debian.org/pkg/libtext-csv-xs-perl","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42198","published":"2026-04-29T00:00:00","updated_at":"2026-05-13T17:04:34.230753+00:00","description":"\npgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to\nbefore version 42.7.11, pgjdbc is vulnerable to a client-side denial of\nservice during SCRAM-SHA-256 authentication. A malicious server can\ninstruct the driver to perform SCRAM authentication with a very large\niteration count. With a large enough value, the client spends an unbounded\namount of CPU time inside PBKDF2 before authentication can fail. A single\nattempt ties up a CPU core. Repeated or concurrent attempts exhaust client\nCPU and can wedge connection pools. In affected versions, loginTimeout did\nnot fully mitigate this problem. When loginTimeout expired, the caller\ncould stop waiting, but the worker thread performing the connection attempt\ncould continue running and burning CPU inside the SCRAM PBKDF2 computation.\nThis issue has been patched in version 42.7.11.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42198","https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-98qh-xjc8-98pq","https://github.com/pgjdbc/pgjdbc/commit/c9d41d1332a7426fcef19ff89f2e6b1116429143 (REL42.7.11)"],"bugs":[""],"patches":{"libpgjava":[]},"tags":{},"packages":[{"name":"libpgjava","source":"https://ubuntu.com/security/cve?package=libpgjava","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpgjava","debian":"https://tracker.debian.org/pkg/libpgjava","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"42.7.11-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40560","published":"2026-04-29T00:00:00","updated_at":"2026-05-14T08:41:12.377817+00:00","description":"\nStarman versions before 0.4018 for Perl allows HTTP Request Smuggling via\nImproper Header Precedence.\nStarman incorrectly prioritizes \"Content-Length\" over \"Transfer-Encoding:\nchunked\" when both headers are present in an HTTP request. Per RFC 7230\n3.3.3, Transfer-Encoding must take precedence.\nAn attacker could exploit this to smuggle malicious HTTP requests via a\nfront-end reverse proxy.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40560","https://lists.security.metacpan.org/cve-announce/msg/39426182/"],"bugs":[""],"patches":{"starman":[]},"tags":{},"packages":[{"name":"starman","source":"https://ubuntu.com/security/cve?package=starman","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=starman","debian":"https://tracker.debian.org/pkg/starman","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-7363","published":"2026-04-28T23:16:00","updated_at":"2026-05-13T16:43:29.953171+00:00","description":"\nUse after free in Canvas in Google Chrome on Linux, ChromeOS prior to\n147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a\nsandbox via a crafted HTML page. (Chromium security severity: Critical)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7363"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-7361","published":"2026-04-28T23:16:00","updated_at":"2026-05-14T07:10:52.235930+00:00","description":"\nUse after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a\nremote attacker to potentially exploit heap corruption via a crafted HTML\npage. (Chromium security severity: Critical)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7361"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-7360","published":"2026-04-28T23:16:00","updated_at":"2026-05-13T16:34:32.050161+00:00","description":"\nInsufficient validation of untrusted input. in Compositing in Google Chrome\nprior to 147.0.7727.138 allowed a remote attacker who had compromised the\nrenderer process to bypass site isolation via a crafted HTML page.\n(Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":3.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7360"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-7359","published":"2026-04-28T23:16:00","updated_at":"2026-05-13T16:20:04.162619+00:00","description":"\nUse after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a\nremote attacker who had compromised the renderer process to potentially\nperform a sandbox escape via a crafted HTML page. (Chromium security\nseverity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7359"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":12840,"limit":20,"total_results":79316}