elsa-2026-55450
oracle_linux
Description
[8.12.1-4.4] - fix proxy environment variable change detection (CVE-2026-8927) [8.12.1-4.el10_2.3] - fix HTTP Negotiate connection reuse auth bypass (CVE-2026-1965) - fix OAuth2 bearer token leak via redirect and netrc (CVE-2026-3783) - fix proxy connection reuse with wrong credentials (CVE-2026-3784) [8.12.1-4.2] - fix SSH host key mismatch on type difference (CVE-2026-9547) - fix schemeless URL handling with --proto-default (CVE-2026-12064) - fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286) [8.12.1-4.1] - openssl: fix CA cache reuse with CURLSSLOPT_NO_PARTIALCHAIN (CVE-2025-14819)
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cves": [
"CVE-2025-14819",
"CVE-2026-12064",
"CVE-2026-1965",
"CVE-2026-3783",
"CVE-2026-3784",
"CVE-2026-8286",
"CVE-2026-9547"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[8.12.1-4.4]\n- fix proxy environment variable change detection (CVE-2026-8927)\n\n[8.12.1-4.el10_2.3]\n- fix HTTP Negotiate connection reuse auth bypass (CVE-2026-1965)\n- fix OAuth2 bearer token leak via redirect and netrc (CVE-2026-3783)\n- fix proxy connection reuse with wrong credentials (CVE-2026-3784)\n\n[8.12.1-4.2]\n- fix SSH host key mismatch on type difference (CVE-2026-9547)\n- fix schemeless URL handling with --proto-default (CVE-2026-12064)\n- fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286)\n\n[8.12.1-4.1]\n- openssl: fix CA cache reuse with CURLSSLOPT_NO_PARTIALCHAIN (CVE-2025-14819)",
"id": "ELSA-2026-55450",
"ovalId": "oval:com.oracle.elsa:def:202655450",
"source": "oracle_linux",
"title": "ELSA-2026-55450: curl security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
}