StackPatch is liveSee product

Back to CVE digest
Ubuntu USN · USN-8227-1

curl vulnerabilities

Published: Mon, 04 May 2026 11:40

CVE-2026-4873CVE-2026-5773CVE-2026-5545CVE-2026-6429CVE-2026-6276CVE-2026-6253CVE-2026-7168

Summary

curl could be made to expose sensitive information over the network.

Details

It was discovered that curl incorrectly reused non-TLS connections when TLS was required in some STARTTLS configurations. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-4873) It was discovered that curl incorrectly reused certain HTTP Negotiate connections. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-5545) It was discovered that curl incorrectly reused certain SMB connections. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-5773) It was discovered that curl could leak proxy credentials when handling redirects in some configurations. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-6253) It was discovered that curl could leak cookies because of stale custom cookie host handling in some requests. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-6276) It was discovered that curl could leak .netrc credentials when reusing proxy connections in some situations. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-6429) It was discovered that curl could leak Digest authentication state when switching proxies in some situations. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-7168)

Recommended actions per Ubuntu release

StackPatch playbook auto-generated per release codename and per affected package.

Ubuntu jammy

  • curl7.81.0-1ubuntu1.24apt_upgrade

    Standard apt upgrade. Install 7.81.0-1ubuntu1.24 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y curl

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • curl7.81.0-1ubuntu1.24apt_upgrade

    Standard apt upgrade. Install 7.81.0-1ubuntu1.24 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y curl

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl3-gnutls7.81.0-1ubuntu1.24apt_upgrade

    Standard apt upgrade. Install 7.81.0-1ubuntu1.24 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl3-gnutls

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl3-nss7.81.0-1ubuntu1.24apt_upgrade

    Standard apt upgrade. Install 7.81.0-1ubuntu1.24 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl3-nss

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl47.81.0-1ubuntu1.24apt_upgrade

    Standard apt upgrade. Install 7.81.0-1ubuntu1.24 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-doc7.81.0-1ubuntu1.24apt_upgrade

    Standard apt upgrade. Install 7.81.0-1ubuntu1.24 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-doc

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-gnutls-dev7.81.0-1ubuntu1.24apt_upgrade

    Standard apt upgrade. Install 7.81.0-1ubuntu1.24 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-gnutls-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-nss-dev7.81.0-1ubuntu1.24apt_upgrade

    Standard apt upgrade. Install 7.81.0-1ubuntu1.24 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-nss-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-openssl-dev7.81.0-1ubuntu1.24apt_upgrade

    Standard apt upgrade. Install 7.81.0-1ubuntu1.24 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-openssl-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

Ubuntu noble

  • curl8.5.0-2ubuntu10.9apt_upgrade

    Standard apt upgrade. Install 8.5.0-2ubuntu10.9 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y curl

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • curl8.5.0-2ubuntu10.9apt_upgrade

    Standard apt upgrade. Install 8.5.0-2ubuntu10.9 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y curl

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl3t64-gnutls8.5.0-2ubuntu10.9apt_upgrade

    Standard apt upgrade. Install 8.5.0-2ubuntu10.9 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl3t64-gnutls

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-doc8.5.0-2ubuntu10.9apt_upgrade

    Standard apt upgrade. Install 8.5.0-2ubuntu10.9 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-doc

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-gnutls-dev8.5.0-2ubuntu10.9apt_upgrade

    Standard apt upgrade. Install 8.5.0-2ubuntu10.9 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-gnutls-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-openssl-dev8.5.0-2ubuntu10.9apt_upgrade

    Standard apt upgrade. Install 8.5.0-2ubuntu10.9 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-openssl-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4t648.5.0-2ubuntu10.9apt_upgrade

    Standard apt upgrade. Install 8.5.0-2ubuntu10.9 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4t64

    Most apt upgrades restart their service automatically. needrestart lists anything else.

Ubuntu questing

  • curl8.14.1-2ubuntu1.3apt_upgrade

    Standard apt upgrade. Install 8.14.1-2ubuntu1.3 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y curl

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • curl8.14.1-2ubuntu1.3apt_upgrade

    Standard apt upgrade. Install 8.14.1-2ubuntu1.3 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y curl

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl3t64-gnutls8.14.1-2ubuntu1.3apt_upgrade

    Standard apt upgrade. Install 8.14.1-2ubuntu1.3 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl3t64-gnutls

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-doc8.14.1-2ubuntu1.3apt_upgrade

    Standard apt upgrade. Install 8.14.1-2ubuntu1.3 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-doc

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-gnutls-dev8.14.1-2ubuntu1.3apt_upgrade

    Standard apt upgrade. Install 8.14.1-2ubuntu1.3 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-gnutls-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-openssl-dev8.14.1-2ubuntu1.3apt_upgrade

    Standard apt upgrade. Install 8.14.1-2ubuntu1.3 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-openssl-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4t648.14.1-2ubuntu1.3apt_upgrade

    Standard apt upgrade. Install 8.14.1-2ubuntu1.3 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4t64

    Most apt upgrades restart their service automatically. needrestart lists anything else.

Ubuntu resolute

  • curl8.18.0-1ubuntu2.1apt_upgrade

    Standard apt upgrade. Install 8.18.0-1ubuntu2.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y curl

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • curl8.18.0-1ubuntu2.1apt_upgrade

    Standard apt upgrade. Install 8.18.0-1ubuntu2.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y curl

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl3t64-gnutls8.18.0-1ubuntu2.1apt_upgrade

    Standard apt upgrade. Install 8.18.0-1ubuntu2.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl3t64-gnutls

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-doc8.18.0-1ubuntu2.1apt_upgrade

    Standard apt upgrade. Install 8.18.0-1ubuntu2.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-doc

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-gnutls-dev8.18.0-1ubuntu2.1apt_upgrade

    Standard apt upgrade. Install 8.18.0-1ubuntu2.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-gnutls-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4-openssl-dev8.18.0-1ubuntu2.1apt_upgrade

    Standard apt upgrade. Install 8.18.0-1ubuntu2.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4-openssl-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • libcurl4t648.18.0-1ubuntu2.1apt_upgrade

    Standard apt upgrade. Install 8.18.0-1ubuntu2.1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y libcurl4t64

    Most apt upgrades restart their service automatically. needrestart lists anything else.

Are YOU affected by USN-8227-1?

5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether USN-8227-1 (and any other live CVE) applies. Anonymous, no signup.

curl https://mindsparkstack.com/scan.sh | bash
Want this automated for your servers?

StackPatch runs this match against YOUR installed packages every hour

Free 1-server / $99 lifetime founder seat (50 only) / $19+/mo monthly. Indie pricing.