JLSEC-2026-1339

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1339.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1339.json
JSON Data
https://api.test.osv.dev/v1/vulns/JLSEC-2026-1339
Upstream
Published
2026-08-17T13:15:13.400Z
Modified
2026-08-17T13:30:03.676810149Z
Severity
Summary
[none]
Details

A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (--ssl-reqd on the command line orCURLOPT_USE_SSL set to CURLUSESSL_CONTROL or CURLUSESSL_ALL withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations withoutTLS contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.

Database specific
{
    "sources": [
        {
            "modified": "2026-06-17T03:38:05.010Z",
            "database_specific": {
                "status": "Modified"
            },
            "id": "CVE-2021-22946",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22946",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2021-22946",
            "imported": "2026-08-16T08:05:12.559Z",
            "published": "2021-09-29T20:15:08.187Z"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / LibCURL_jll

Package

Name
LibCURL_jll
Purl
pkg:julia/LibCURL_jll?uuid=deac9b47-8bc7-5906-a0fe-35ac56dc84c0

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.81.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1339.json"