{"id":"CLSA-2026-1774260216","summary":"Fix CVE(s): CVE-2026-1965, CVE-2026-3783, CVE-2026-3784","details":"   * SECURITY UPDATE: reuse of connections using HTTP Negotiate\n     - debian/patches/CVE-2026-1965.patch: fix reuse of connections using\n       HTTP Negotiate and fix copy and paste url_match_auth_nego mistake.\n     - CVE-2026-1965\n   * Bearer token sent without checking auth is allowed\n     - debian/patches/CVE-2026-3783.patch: only send bearer if auth is\n       allowed.\n     - CVE-2026-3783\n   * Proxy credential reuse across different credentials\n     - debian/patches/CVE-2026-3784.patch: compare proxy credentials in\n       proxy_info_matches to prevent connection reuse with wrong auth.\n     - CVE-2026-3784","modified":"2026-06-04T09:45:21.224693738Z","published":"2026-03-23T10:03:44Z","upstream":["CVE-2026-1965","CVE-2026-3783","CVE-2026-3784"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1774260216.html"}],"affected":[{"package":{"name":"curl","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/curl?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.64.0-4+deb10u9+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1774260216.json"}},{"package":{"name":"libcurl3-gnutls","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libcurl3-gnutls?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.64.0-4+deb10u9+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1774260216.json"}},{"package":{"name":"libcurl3-nss","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libcurl3-nss?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.64.0-4+deb10u9+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1774260216.json"}},{"package":{"name":"libcurl4","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libcurl4?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.64.0-4+deb10u9+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1774260216.json"}},{"package":{"name":"libcurl4-doc","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libcurl4-doc?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.64.0-4+deb10u9+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1774260216.json"}},{"package":{"name":"libcurl4-gnutls-dev","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libcurl4-gnutls-dev?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.64.0-4+deb10u9+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1774260216.json"}},{"package":{"name":"libcurl4-nss-dev","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libcurl4-nss-dev?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.64.0-4+deb10u9+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1774260216.json"}},{"package":{"name":"libcurl4-openssl-dev","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libcurl4-openssl-dev?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.64.0-4+deb10u9+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1774260216.json"}}],"schema_version":"1.7.5"}