Security update for curl
This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-5545: wrong reuse of HTTP Negotiate connection (bsc#1262632). - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-6253: proxy credentials leak over redirect-to proxy (bsc#1262635). - CVE-2026-6276: stale custom cookie host causes cookie leak (bsc#1262636). - CVE-2026-6429: netrc credential leak with reused proxy connection (bsc#1262638).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-5545: wrong reuse of HTTP Negotiate connection (bsc#1262632). - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-6253: proxy credentials leak over redirect-to proxy (bsc#1262635). - CVE-2026-6276: stale custom cookie host causes cookie leak (bsc#1262636). - CVE-2026-6429: netrc credential leak with reused proxy connection (bsc#1262638).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1262631
- https://bugzilla.suse.com/1262632
- https://bugzilla.suse.com/1262633
- https://bugzilla.suse.com/1262635
- https://bugzilla.suse.com/1262636
- https://bugzilla.suse.com/1262638
- https://www.suse.com/security/cve/CVE-2026-4873
- https://www.suse.com/security/cve/CVE-2026-5545
- https://www.suse.com/security/cve/CVE-2026-5773
- https://www.suse.com/security/cve/CVE-2026-6253
- https://www.suse.com/security/cve/CVE-2026-6276
- https://www.suse.com/security/cve/CVE-2026-6429
- https://www.suse.com/support/update/announcement/2026/suse-su-20262703-1/