stable

curl-8.15.0-8.fc43

FEDORA-2026-097fb2e7e9 created by jamacku a week ago for Fedora 43
  • fix cross-proxy Digest auth state leak (CVE-2026-7168)
  • fix cross-origin Digest auth state leak (CVE-2026-11856)
  • fix password leak with netrc and user in URL (CVE-2026-8926)
  • fix SSH improper host validation (CVE-2026-9547)
  • fix trailing dot domain super cookie (CVE-2026-8924)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-097fb2e7e9

This update has been submitted for testing by jamacku.

a week ago

This update's test gating status has been changed to 'waiting'.

a week ago

This update's test gating status has been changed to 'waiting'.

a week ago

This update's test gating status has been changed to 'passed'.

a week ago

This update has been pushed to testing.

a week ago
User Icon filiperosset commented & provided feedback a week ago
karma

there are no regressions found from my side

User Icon ephmo provided feedback a week ago
karma
BZ#2480086 CVE-2026-7168 curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse [fedora-all]
BZ#2497410 CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
BZ#2497475 CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
BZ#2497597 CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
BZ#2498017 CVE-2026-11856 curl: curl: Information disclosure via incorrect Digest authentication header reuse [fedora-all]
Test Case curl

This update can be pushed to stable now if the maintainer wishes

a week ago
User Icon gilwooden provided feedback a week ago
karma
Test Case curl

This update has been submitted for stable by bodhi.

a week ago

This update has been pushed to stable.

a week ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
3
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
a week ago
in testing
a week ago
in stable
a week ago
approved
a week ago
BZ#2480086 CVE-2026-7168 curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse [fedora-all]
0
1
BZ#2497410 CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
0
1
BZ#2497475 CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
0
1
BZ#2497597 CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
0
1
BZ#2498017 CVE-2026-11856 curl: curl: Information disclosure via incorrect Digest authentication header reuse [fedora-all]
0
1

Automated Test Results

Test Cases

0 2 Test Case curl