{"cves":["CVE-2026-8927"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[8.12.1-4.4]\n- fix proxy environment variable change detection (CVE-2026-8927)\n\n[8.12.1-4.el10_2.3]\n- fix HTTP Negotiate connection reuse auth bypass (CVE-2026-1965)\n- fix OAuth2 bearer token leak via redirect and netrc (CVE-2026-3783)\n- fix proxy connection reuse with wrong credentials (CVE-2026-3784)\n\n[8.12.1-4.2]\n- fix SSH host key mismatch on type difference (CVE-2026-9547)\n- fix schemeless URL handling with --proto-default (CVE-2026-12064)\n- fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286)\n\n[8.12.1-4.1]\n- openssl: fix CA cache reuse with CURLSSLOPT_NO_PARTIALCHAIN (CVE-2025-14819)","id":"ELSA-2026-55432","ovalId":"oval:com.oracle.elsa:def:202655432","source":"oracle_linux","title":"ELSA-2026-55432:  curl security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-55432.html"}