stable

curl-8.18.0-8.fc44

FEDORA-2026-e691fbbfe7 created by jamacku a month ago for Fedora 44
  • Fix trailing dot domain super cookie (CVE-2026-8924)
  • Fix SSH improper host validation (CVE-2026-9547)
  • Fix password leak with netrc and user in URL (CVE-2026-8926)
  • Fix cross-origin Digest auth state leak (CVE-2026-11856)
  • Fix cross-proxy Digest auth state leak (CVE-2026-7168)
  • Fix OCSP stapling bypass with Apple SecTrust (CVE-2026-7009)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-e691fbbfe7

This update has been submitted for testing by jamacku.

a month ago

This update's test gating status has been changed to 'waiting'.

a month ago

This update's test gating status has been changed to 'waiting'.

a month ago

This update's test gating status has been changed to 'passed'.

a month ago

This update has been pushed to testing.

a month ago
User Icon filiperosset commented & provided feedback a month ago
karma

no regressions noted in normal F44 daily usage

User Icon ephmo provided feedback a month ago
karma
BZ#2480086 CVE-2026-7168 curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse [fedora-all]
BZ#2491327 CVE-2026-7009 curl: Curl: Certificate validation bypass due to OCSP stapling flaw [fedora-all]
BZ#2497410 CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
BZ#2497475 CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
BZ#2497597 CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
BZ#2498017 CVE-2026-11856 curl: curl: Information disclosure via incorrect Digest authentication header reuse [fedora-all]
Test Case curl

This update can be pushed to stable now if the maintainer wishes

a month ago
User Icon bojan commented & provided feedback a month ago
karma

Works.

This update has been submitted for stable by bodhi.

a month ago
karma

This update has been pushed to stable.

a month ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
4
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
a month ago
in testing
a month ago
in stable
a month ago
approved
a month ago
BZ#2480086 CVE-2026-7168 curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse [fedora-all]
0
1
BZ#2491327 CVE-2026-7009 curl: Curl: Certificate validation bypass due to OCSP stapling flaw [fedora-all]
0
1
BZ#2497410 CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
0
1
BZ#2497475 CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
0
1
BZ#2497597 CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
0
1
BZ#2498017 CVE-2026-11856 curl: curl: Information disclosure via incorrect Digest authentication header reuse [fedora-all]
0
1

Automated Test Results

Test Cases

0 1 Test Case curl