[Git][security-tracker-team/security-tracker][master] Add more curl issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 2 08:16:46 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b6b00e4c by Salvatore Bonaccorso at 2026-09-02T09:16:31+02:00
Add more curl issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -452,6 +452,27 @@ CVE-2024-35585 (Oxford Nanopore MinKNOW before 24.06 relies on a client's source
 	TODO: check
 CVE-2023-54391 (Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentic ...)
 	TODO: check
+CVE-2026-80230
+	- curl 8.22.0~rc3-1
+	NOTE: https://curl.se/docs/CVE-2026-80230.html
+	NOTE: Introduced with: https://github.com/curl/curl/8363656cb4e0c60a11d8531ead0ec43120b50591 (curl-7_45_0)
+	NOTE: Fixed by: https://github.com/curl/curl/commit/5267ed859d545534d0c21675a2b70af5a3b6e3ef (rc-8_22_0-3)
+CVE-2026-80229
+	- curl 8.22.0~rc3-1
+	[bookworm] - curl <not-affected> (Vulnerable code introduced later)
+	NOTE: https://curl.se/docs/CVE-2026-80229.html
+	NOTE: Introduced with: https://github.com/curl/curl/f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 (rc-8_14_0-1)
+	NOTE: Fixed by: https://github.com/curl/curl/commit/7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb (rc-8_22_0-3)
+CVE-2026-19931
+	- curl 8.22.0~rc2-1
+	NOTE: https://curl.se/docs/CVE-2026-19931.html
+	NOTE: Introduced with: https://github.com/curl/curl/6c6035532383e300c712e4c1cd9fdd749ed5cf59 (curl-7_64_1)
+	NOTE: Fixed by: https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d05d02fa9eeba533f2f (rc-8_22_0-2)
+CVE-2026-18924
+	- curl 8.22.0~rc2-1
+	NOTE: https://curl.se/docs/CVE-2026-18924.html
+	NOTE: Introduced with: https://github.com/curl/curl/ea7134ac874a66107e54ff93657ac565cf2ec4aa (curl-7_44_0)
+	NOTE: Fixed by: https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43 (rc-8_22_0-1)
 CVE-2026-13608
 	- curl 8.22.0~rc2-1
 	NOTE: https://curl.se/docs/CVE-2026-13608.html



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6b00e4cb98c90af567fd66309527e0065d86a4d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6b00e4cb98c90af567fd66309527e0065d86a4d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/9268d9ce/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list