Skip to content
Ubuntu 26.04 Curl Critical Client Certificate Info Exposure USN-8670

Ubuntu 26.04 Curl Critical Client Certificate Info Exposure USN-8670

Linuxsecurity LinuxSecurity Advisories September 9, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

curl could be made to expose sensitive information. Software Description: - curl: HTTP, HTTPS, and FTP client and client libraries Details: USN-8670-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: Joshua Rogers discovered that curl incorrectly handled reusing connections when client certificate settings changed. This could result in the wrong client certificates being used, contrary to expectations.

curl could be made to expose sensitive information.

Software Description:

- curl: HTTP, HTTPS, and FTP client and client libraries

USN-8670-1 fixed a vulnerability in curl. This update provides the

corresponding update for Ubuntu 26.04 LTS.

Original advisory details:

Joshua Rogers discovered that curl incorrectly handled reusing

connections when client certificate settings changed. This could result

in the wrong client certificates being used, contrary to expectations.

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS curl 8.18.0-1ubuntu2.5 libcurl3t64-gnutls 8.18.0-1ubuntu2.5 libcurl4-gnutls-dev 8.18.0-1ubuntu2.5 libcurl4-openssl-dev 8.18.0-1ubuntu2.5 libcurl4t64 8.18.0-1ubuntu2.5 In general, a standard system update will make all the necessary changes.

Ubuntu Security Notice USN-8670-3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)