{"cves":["CVE-2025-14819","CVE-2026-12064","CVE-2026-1965","CVE-2026-3783","CVE-2026-3784","CVE-2026-8286","CVE-2026-9547"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[8.12.1-4.4]\n- fix proxy environment variable change detection (CVE-2026-8927)\n\n[8.12.1-4.el10_2.3]\n- fix HTTP Negotiate connection reuse auth bypass (CVE-2026-1965)\n- fix OAuth2 bearer token leak via redirect and netrc (CVE-2026-3783)\n- fix proxy connection reuse with wrong credentials (CVE-2026-3784)\n\n[8.12.1-4.2]\n- fix SSH host key mismatch on type difference (CVE-2026-9547)\n- fix schemeless URL handling with --proto-default (CVE-2026-12064)\n- fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286)\n\n[8.12.1-4.1]\n- openssl: fix CA cache reuse with CURLSSLOPT_NO_PARTIALCHAIN (CVE-2025-14819)","id":"ELSA-2026-55450","ovalId":"oval:com.oracle.elsa:def:202655450","source":"oracle_linux","title":"ELSA-2026-55450:  curl security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-55450.html"}