Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
JLSEC-2026-1197
  • Julia/CURL_jll
  • Julia/LibCURL_jll
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream... yesterday
  • Fix available
  • Severity - 9.8 (Critical)
JLSEC-2026-1198
  • Julia/CURL_jll
  • Julia/LibCURL_jll
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote... yesterday
  • Fix available
  • Severity - 7.5 (High)
JLSEC-2026-1199
  • Julia/CURL_jll
  • Julia/LibCURL_jll
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse... yesterday
  • Fix available
  • Severity - 9.1 (Critical)
JLSEC-2026-1200
  • Julia/CURL_jll
  • Julia/LibCURL_jll
By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper... yesterday
  • Fix available
  • Severity - 7.5 (High)
JLSEC-2026-1201
  • Julia/CURL_jll
  • Julia/LibCURL_jll
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest**... yesterday
  • Fix available
  • Severity - 9.8 (Critical)
JLSEC-2026-1202
  • Julia/CURL_jll
  • Julia/LibCURL_jll
When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a... yesterday
  • Fix available
  • Severity - 7.5 (High)
JLSEC-2026-1203
  • Julia/CURL_jll
  • Julia/LibCURL_jll
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing... yesterday
  • Fix available
  • Severity - 5.9 (Medium)
JLSEC-2026-1204
  • Julia/CURL_jll
  • Julia/LibCURL_jll
libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated... yesterday
  • Fix available
  • Severity - 6.5 (Medium)
JLSEC-2026-1205
  • Julia/CURL_jll
  • Julia/LibCURL_jll
libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl... yesterday
  • Fix available
  • Severity - 7.5 (High)
JLSEC-2026-1206
  • Julia/CURL_jll
  • Julia/LibCURL_jll
See record for full details yesterday
  • Fix available
  • Severity - 5.9 (Medium)
JLSEC-2026-1207
  • Julia/CURL_jll
  • Julia/LibCURL_jll
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request... yesterday
  • Fix available
  • Severity - 7.5 (High)
JLSEC-2026-1208
  • Julia/CURL_jll
  • Julia/LibCURL_jll
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl... yesterday
  • Fix available
  • Severity - 5.3 (Medium)
JLSEC-2026-1209
  • Julia/CURL_jll
  • Julia/LibCURL_jll
When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP... yesterday
  • Fix available
  • Severity - 5.3 (Medium)
JLSEC-2026-1210
  • Julia/CURL_jll
  • Julia/LibCURL_jll
Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest**... yesterday
  • Fix available
  • Severity - 5.3 (Medium)
JLSEC-2026-1211
  • Julia/CURL_jll
  • Julia/LibCURL_jll
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might... yesterday
  • Fix available
  • Severity - 8.1 (High)
JLSEC-2026-1212
  • Julia/CURL_jll
  • Julia/LibCURL_jll
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate... yesterday
  • Fix available
  • Severity - 6.5 (Medium)