elsa-2026-55450

oracle_linux
Description

[8.12.1-4.4] - fix proxy environment variable change detection (CVE-2026-8927) [8.12.1-4.el10_2.3] - fix HTTP Negotiate connection reuse auth bypass (CVE-2026-1965) - fix OAuth2 bearer token leak via redirect and netrc (CVE-2026-3783) - fix proxy connection reuse with wrong credentials (CVE-2026-3784) [8.12.1-4.2] - fix SSH host key mismatch on type difference (CVE-2026-9547) - fix schemeless URL handling with --proto-default (CVE-2026-12064) - fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286) [8.12.1-4.1] - openssl: fix CA cache reuse with CURLSSLOPT_NO_PARTIALCHAIN (CVE-2025-14819)

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2025-14819",
    "CVE-2026-12064",
    "CVE-2026-1965",
    "CVE-2026-3783",
    "CVE-2026-3784",
    "CVE-2026-8286",
    "CVE-2026-9547"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[8.12.1-4.4]\n- fix proxy environment variable change detection (CVE-2026-8927)\n\n[8.12.1-4.el10_2.3]\n- fix HTTP Negotiate connection reuse auth bypass (CVE-2026-1965)\n- fix OAuth2 bearer token leak via redirect and netrc (CVE-2026-3783)\n- fix proxy connection reuse with wrong credentials (CVE-2026-3784)\n\n[8.12.1-4.2]\n- fix SSH host key mismatch on type difference (CVE-2026-9547)\n- fix schemeless URL handling with --proto-default (CVE-2026-12064)\n- fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286)\n\n[8.12.1-4.1]\n- openssl: fix CA cache reuse with CURLSSLOPT_NO_PARTIALCHAIN (CVE-2025-14819)",
  "id": "ELSA-2026-55450",
  "ovalId": "oval:com.oracle.elsa:def:202655450",
  "source": "oracle_linux",
  "title": "ELSA-2026-55450:  curl security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
}
View JSON API Download JSON