Skip to content
Critical Curl Vulnerabilities in Fedora 44 and 43 Released

Critical Curl Vulnerabilities in Fedora 44 and 43 Released

First seen 11 Sep 2026, 04:46 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 07:17 UTC

On September 8, 2026, Fedora released updates addressing critical vulnerabilities in curl affecting versions 44 and 43. The vulnerabilities include a use-after-free issue (CVE-2026-10536), a proxy password leak (CVE-2026-9079), a certificate validation bypass (CVE-2026-11564), and unauthorized connection reuse (CVE-2026-8458). These vulnerabilities could potentially lead to denial of service and information disclosure. The affected systems are primarily Linux distributions utilizing curl for data transfer. Users are advised to apply the updates immediately using the 'dnf' update program. The vulnerabilities were published on July 3, 2026, and have been confirmed in both Fedora versions. The updates are crucial for maintaining system security and preventing potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-03
CVE-2026-10536 published
A use-after-free vulnerability in curl leading to denial of service was disclosed.
Linuxsecurity
2026-07-03
CVE-2026-9079 published
Information disclosure due to failure to clear proxy authentication credentials was disclosed.
Linuxsecurity
2026-07-03
CVE-2026-11564 published
Certificate validation bypass due to incorrect connection reuse was disclosed.
Linuxsecurity
2026-07-03
CVE-2026-8458 published
Unauthorized connection reuse due to a logical error was disclosed.
Linuxsecurity
2026-09-08
Fedora updates released
Fedora released updates for curl addressing critical vulnerabilities in versions 44 and 43.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-10536 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed