[CLSA-2026:1779372929] curl: Fix of CVE-2026-7168
Type:
security
Severity:
None
Release date:
2026-05-22 17:59:09 UTC
Description:
- CVE-2026-7168: clear proxy Digest auth state when CURLOPT_PROXY is reassigned to a different proxy host on the same easy handle so a stale Proxy-Authorization header is not replayed to the new proxy
Updated packages:
  • curl-7.76.1-31.el9_2.1.tuxcare.els12.x86_64.rpm
    sha:89552f23dc03b42a14ad342b7e4378ce138ad86dedc35fc7e54b7e2bcd581dfb
  • curl-minimal-7.76.1-31.el9_2.1.tuxcare.els12.x86_64.rpm
    sha:3cdc05caa2028cfc38312c94f65df560e2f7e4ec1af87e879de896c9a7ce2b9b
  • libcurl-7.76.1-31.el9_2.1.tuxcare.els12.i686.rpm
    sha:fb94ea961a5a2381ad3fa79c07ed0b212cc4fa6e6decfe15bd80fa7bf1158df4
  • libcurl-7.76.1-31.el9_2.1.tuxcare.els12.x86_64.rpm
    sha:54786d840d57b55bc890c8b644ecdec462a89eead446fef529b0e238181946f0
  • libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els12.i686.rpm
    sha:36016bb3d11df19d92979f46e1469ccd4893b96e510aa690b9b30c782079e8ff
  • libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els12.x86_64.rpm
    sha:cd591063d0e29ffcd1d7c602f56566f9793472572a201f01643014ac53f8120e
  • libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els12.i686.rpm
    sha:38c4e19e6a450d2c6c1e3e82ba6d0de6352e3074ea26a54c79a4706ba7d8bc25
  • libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els12.x86_64.rpm
    sha:a98c382b60af0673064a93d295ca5a5d5d407b6452eb293b8cd65cc725108923
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.