{"id":"USN-8670-3","summary":"curl vulnerability","details":"USN-8670-1 fixed a vulnerability in curl. This update provides the\ncorresponding update for Ubuntu 26.04 LTS.\n\nOriginal advisory details:\n\n Joshua Rogers discovered that curl incorrectly handled reusing\n connections when client certificate settings changed. This could result\n in the wrong client certificates being used, contrary to expectations.","modified":"2026-09-10T00:56:42.827702883Z","published":"2026-09-08T17:20:54Z","related":["UBUNTU-CVE-2026-8932"],"upstream":["CVE-2026-8932","UBUNTU-CVE-2026-8932"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8670-3"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-8932"}],"affected":[{"package":{"name":"curl","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/curl?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.18.0-1ubuntu2.5"}]}],"versions":["8.14.1-2ubuntu1","8.17.0-1ubuntu1","8.18.0-1ubuntu1","8.18.0-1ubuntu2","8.18.0-1ubuntu2.1","8.18.0-1ubuntu2.2","8.18.0-1ubuntu2.3","8.18.0-1ubuntu2.4"],"ecosystem_specific":{"binaries":[{"binary_name":"curl","binary_version":"8.18.0-1ubuntu2.5"},{"binary_name":"libcurl3t64-gnutls","binary_version":"8.18.0-1ubuntu2.5"},{"binary_name":"libcurl4t64","binary_version":"8.18.0-1ubuntu2.5"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:26.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-8932"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8670-3.json"}}],"schema_version":"1.9.0"}