Skip to main content
Early Access
— Mondoo Vulnerability Intelligence is currently in preview.
Vulnerability Intelligence
Login
Get Demo
SUSE-SU-2026:0050-1 | Mondoo Vulnerability Intelligence
Back to search
SUSE-SU-2026:0050-1
UNKNOWN
Security update for curl
Published Jan 7, 2026
Modified 1 weeks ago
Fix available
Details
This update for curl fixes the following issues:
CVE-2025-14524: bearer token leak on cross-protocol redirect (bsc#1255731).
CVE-2025-14819: libssh global knownhost override (bsc#1255732).
CVE-2025-15079: libssh key passphrase bypass without agent set (bsc#1255733).
CVE-2025-15224: OpenSSL partial chain store policy bypass (bsc#1255734).
Affected Packages
openSUSE:Leap 15.6
curl
Fixed in:
8.14.1-150600.4.34.1
openSUSE:Leap 15.6
libcurl-devel
Fixed in:
8.14.1-150600.4.34.1
openSUSE:Leap 15.6
libcurl-devel-32bit
Fixed in:
8.14.1-150600.4.34.1
openSUSE:Leap 15.6
libcurl4
Fixed in:
8.14.1-150600.4.34.1
openSUSE:Leap 15.6
libcurl4-32bit
Fixed in:
8.14.1-150600.4.34.1
References
REPORT
https://bugzilla.suse.com/1255731
REPORT
https://bugzilla.suse.com/1255732
REPORT
https://bugzilla.suse.com/1255733
REPORT
https://bugzilla.suse.com/1255734
WEB
https://www.suse.com/security/cve/CVE-2025-14524
WEB
https://www.suse.com/security/cve/CVE-2025-14819
WEB
https://www.suse.com/security/cve/CVE-2025-15079
WEB
https://www.suse.com/security/cve/CVE-2025-15224
ADVISORY
https://www.suse.com/support/update/announcement/2026/suse-su-20260050-1/
Upstream
CVE-2025-14524
CVE-2025-14819
CVE-2025-15079
CVE-2025-15224
Related
CVE-2025-14524
CVE-2025-14819
CVE-2025-15079
CVE-2025-15224
Ecosystems
openSUSE Leap 15.6
Timeline
Published
Jan 7, 2026
Modified
Jan 7, 2026