[Git][security-tracker-team/security-tracker][master] Add new curl issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 2 08:39:21 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
49919883 by Salvatore Bonaccorso at 2026-09-02T09:39:12+02:00
Add new curl issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -452,31 +452,54 @@ CVE-2024-35585 (Oxford Nanopore MinKNOW before 24.06 relies on a client's source
 	TODO: check
 CVE-2023-54391 (Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentic ...)
 	TODO: check
+CVE-2026-82209
+	- curl 8.22.0-1
+	NOTE: https://curl.se/docs/CVE-2026-82209.html
+	NOTE: Introduced with: https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465 (curl-7_46_0)
+	NOTE: Fixed by: https://github.com/curl/curl/commit/95c1e8915dce64606bd753fd47fc0bd236e31cd6 (curl-8_22_0)
+CVE-2026-82208
+	- curl 8.22.0-1 (unimportant)
+	[bookworm] - curl <not-affected> (Vulnerable code introduced later)
+	NOTE: https://curl.se/docs/CVE-2026-82208.html
+	NOTE: Introduced with: https://github.com/curl/curl/commit/0f2876b2c33f6784a27b6f7345bd8cd95b46352a (curl-8_9_1)
+	NOTE: Fixed by: https://github.com/curl/curl/commit/ed0338befd1d865a8ea1fbaa90013a096dedd07a (curl-8_22_0)
+	NOTE: curl in Debian not built with wolfSSL support
+CVE-2026-80255
+	- curl 8.22.0-1
+	[bookworm] - curl <not-affected> (Vulnerable code introduced later)
+	NOTE: https://curl.se/docs/CVE-2026-80255.html
+	NOTE: Introduced with: https://github.com/curl/curl/commit/1aea05a6c2699e80c75936d58569851555acd603 (curl-8_13_0)
+	NOTE: Fixed by: https://github.com/curl/curl/commit/4f6aa41a0145e930e766775dbe860883d350aa0a (curl-8_22_0)
+CVE-2026-80231
+	- curl <not-affected> (Only affects Curl on Windows and macOS)
+	NOTE: https://curl.se/docs/CVE-2026-80231.html
+	NOTE: Introduced with: https://github.com/curl/curl/commit/148534db57dda611cf8516e92e4d6e35fc1e5074 (curl-7_71_0)
+	NOTE: Fixed by: https://github.com/curl/curl/commit/7be1e70cb6bcd83e130ecfe8cb91b6a7dcdeff42 (rc-8_22_0-3)
 CVE-2026-80230
 	- curl 8.22.0~rc3-1
 	NOTE: https://curl.se/docs/CVE-2026-80230.html
-	NOTE: Introduced with: https://github.com/curl/curl/8363656cb4e0c60a11d8531ead0ec43120b50591 (curl-7_45_0)
+	NOTE: Introduced with: https://github.com/curl/curl/commit/8363656cb4e0c60a11d8531ead0ec43120b50591 (curl-7_45_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/5267ed859d545534d0c21675a2b70af5a3b6e3ef (rc-8_22_0-3)
 CVE-2026-80229
 	- curl 8.22.0~rc3-1
 	[bookworm] - curl <not-affected> (Vulnerable code introduced later)
 	NOTE: https://curl.se/docs/CVE-2026-80229.html
-	NOTE: Introduced with: https://github.com/curl/curl/f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 (rc-8_14_0-1)
+	NOTE: Introduced with: https://github.com/curl/curl/commit/f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 (rc-8_14_0-1)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb (rc-8_22_0-3)
 CVE-2026-19931
 	- curl 8.22.0~rc2-1
 	NOTE: https://curl.se/docs/CVE-2026-19931.html
-	NOTE: Introduced with: https://github.com/curl/curl/6c6035532383e300c712e4c1cd9fdd749ed5cf59 (curl-7_64_1)
+	NOTE: Introduced with: https://github.com/curl/curl/commit/6c6035532383e300c712e4c1cd9fdd749ed5cf59 (curl-7_64_1)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d05d02fa9eeba533f2f (rc-8_22_0-2)
 CVE-2026-18924
 	- curl 8.22.0~rc2-1
 	NOTE: https://curl.se/docs/CVE-2026-18924.html
-	NOTE: Introduced with: https://github.com/curl/curl/ea7134ac874a66107e54ff93657ac565cf2ec4aa (curl-7_44_0)
+	NOTE: Introduced with: https://github.com/curl/curl/commit/ea7134ac874a66107e54ff93657ac565cf2ec4aa (curl-7_44_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43 (rc-8_22_0-1)
 CVE-2026-13608
 	- curl 8.22.0~rc2-1
 	NOTE: https://curl.se/docs/CVE-2026-13608.html
-	NOTE: Introduced with: https://github.com/curl/curl/eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4 (curl-7_82_0)
+	NOTE: Introduced with: https://github.com/curl/curl/commit/eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4 (curl-7_82_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/ea71c3b6b60e563651ea8596a975aef0c8199519 (rc-8_22_0-1)
 CVE-2026-84470 (A flaw was found in Ansible Automation Platform's automation-controlle ...)
 	NOT-FOR-US: automation-controller/AWX



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/49919883455dba32e3ad1dd564167ebab20040e4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/49919883455dba32e3ad1dd564167ebab20040e4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/b3050b7b/attachment.htm>


More information about the debian-security-tracker-commits mailing list