Back Linuxsecurity Oracle Linux curl Important Update ELSA-2026
Find practical guidance for preventing, investigating, and responding to Linux security problems. Review Linux Privileges ×
[8.12.1-4.4] - fix proxy environment variable change detection (CVE-2026-8927) [8.12.1-4.el10_2.3] - fix HTTP Negotiate connection reuse auth bypass (CVE-2026-1965) - fix OAuth2 bearer token leak via redirect and netrc (CVE-2026-3783) - fix proxy connection reuse with wrong credentials (CVE-2026-3784) [8.12.1-4.2] - fix SSH host key mismatch on type difference (CVE-2026-9547) - fix schemeless URL handling with --proto-default (CVE-2026-12064) - fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286) [8.12.1-4.1] - openssl: fix CA cache reuse with CURLSSLOPT_NO_PARTIALCHAIN (CVE-2025-14819)
[8.12.1-4.4] - fix proxy environment variable change detection (CVE-2026-8927) [8.12.1-4.el10_2.3] - fix HTTP Negotiate connection reuse auth bypass (CVE-2026-1965) - fix OAuth2 bearer token leak via redirect and netrc (CVE-2026-3783) - fix proxy connection reuse with wrong credentials (CVE-2026-3784) [8.12.1-4.2] - fix SSH host key mismatch on type difference (CVE-2026-9547) - fix schemeless URL handling with --proto-default (CVE-2026-12064) - fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286) [8.12.1-4.1] - openssl: fix CA cache reuse with CURLSSLOPT_NO_PARTIALCHAIN (CVE-2025-14819)
curl-8.12.1-4.el10_2.4.x86_64.rpm libcurl-8.12.1-4.el10_2.4.x86_64.rpm libcurl-devel-8.12.1-4.el10_2.4.x86_64.rpm libcurl-minimal-8.12.1-4.el10_2.4.x86_64.rpm
curl-8.12.1-4.el10_2.4.x86_64.rpm libcurl-8.12.1-4.el10_2.4.x86_64.rpm libcurl-devel-8.12.1-4.el10_2.4.x86_64.rpm libcurl-minimal-8.12.1-4.el10_2.4.x86_64.rpm
curl-8.12.1-4.el10_2.4.aarch64.rpm libcurl-8.12.1-4.el10_2.4.aarch64.rpm libcurl-devel-8.12.1-4.el10_2.4.aarch64.rpm libcurl-minimal-8.12.1-4.el10_2.4.aarch64.rpm
curl-8.12.1-4.el10_2.4.aarch64.rpm libcurl-8.12.1-4.el10_2.4.aarch64.rpm libcurl-devel-8.12.1-4.el10_2.4.aarch64.rpm libcurl-minimal-8.12.1-4.el10_2.4.aarch64.rpm
Related CVEs: CVE-2025-14819 CVE-2026-1965 CVE-2026-3783 CVE-2026-3784 CVE-2026-8286 CVE-2026-9547 CVE-2026-12064
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
