Summary:
An update for curl is now available for EulerOS V2.0SP10(x86_64)
EulerOS Security has rated this update as having a security impact of Critical.A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.General:
curl is a command line tool for transferring data with URL syntax, supporting FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3 and RTSP. curl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, cookies, user+password authentication (Basic, Digest, NTLM, Negotiate, kerberos...), file transfer resume, proxy tunneling and a busload of other useful tricks.
Security Fix(es):
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.(CVE-2026-8286)
['Hello friends,', 'CVE-2026-8286: wrong STARTTLS connection reuse (LOW)', 'CVE-2026-8458: wrong reuse for different services (LOW)', 'CVE-2026-8924: traling dot domain super cookie (LOW)', 'CVE-2026-8925: SASL double-free (MEDIUM)', 'CVE-2026-8926: password leak with netrc and user in URL (LOW)', 'CVE-2026-8927: env-set cross-proxy Digest auth state leak (MEDIUM)', 'CVE-2026-8932: incomplete mTLS config matching in conn reuse (LOW)', 'CVE-2026-9079: stale proxy password leak (MEDIUM)', 'CVE-2026-9080: UAF after pause in socket callback (LOW)', 'CVE-2026-9545: exposing HTTP/3 early data (LOW)', 'CVE-2026-9546: sending old referer (LOW)', 'CVE-2026-9547: SSH improper host validation (LOW)', 'CVE-2026-10536: HTTP/2 stream-dependency tree UAF (LOW)', 'CVE-2026-11352: QUIC zero-length UDP datagrams busy-loop (LOW)', 'CVE-2026-11564: Native CA trust persist (LOW)', 'CVE-2026-11586: WS Auto-PONG memory exhaustion (LOW)', 'CVE-2026-11856: cross-origin Digest auth state...
7.71.1-4.h31.r11.eulerosv2r107.71.1-4.h31.r11.eulerosv2r107.71.1-4.h31.r11.eulerosv2r107.71.1-4.h31.r11.eulerosv2r10Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:HI:HA:N9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N