Multiple CVEs Addressed in Oracle Linux curl Updates

Multiple CVEs Addressed in Oracle Linux curl Updates

First seen 20 Aug 2026, 11:54 UTC Linuxsecurity 92% similarity 72.5

Article Content

Browse articles
ThreatCluster

Oracle has released important updates for its curl software, addressing multiple vulnerabilities. The updates include fixes for CVE-2026-1965 and CVE-2026-3783, which involve HTTP Negotiate connection reuse and OAuth2 bearer token leaks, respectively. Additionally, CVE-2026-9547 and CVE-2026-8286 are also addressed, targeting SSH host key mismatches and TLS connection reuse vulnerabilities. The vulnerabilities affect various versions of curl and libcurl across different architectures, including x86_64 and aarch64. System administrators are advised to apply these updates promptly to mitigate potential security risks. The updates were published on 2026-08-20, with previous CVEs disclosed earlier in 2026. These vulnerabilities could lead to unauthorized access and data leakage if not patched.

Key Points: • Oracle released critical updates for curl addressing multiple CVEs. • Vulnerabilities include OAuth2 token leaks and connection reuse issues. • System administrators must apply updates to prevent potential exploits.

ThreatCluster AI How this analysis works

Timeline

2026-01-08
CVE-2025-14819 published
A vulnerability in OpenSSL affecting CA cache reuse was disclosed.
Linuxsecurity
2026-03-11
CVE-2026-1965 and CVE-2026-3783 published
Vulnerabilities related to HTTP Negotiate auth bypass and OAuth2 token leaks were disclosed.
Linuxsecurity
2026-03-11
CVE-2026-3784 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-03
CVE-2026-9547 and CVE-2026-8286 published
Vulnerabilities affecting SSH host key mismatches and TLS connection reuse were disclosed.
Linuxsecurity
2026-07-03
CVE-2026-8927 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-03
CVE-2026-12064 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
Oracle releases important curl updates
Oracle published updates for curl addressing multiple vulnerabilities, urging immediate application.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story