[CLSA-2026:1779372207] curl: Fix of CVE-2026-7168
Type:
security
Severity:
None
Release date:
2026-05-22 17:52:02 UTC
Description:
- CVE-2026-7168: clear proxy Digest auth state when CURLOPT_PROXY is reassigned to a different proxy host on the same easy handle so a stale Proxy-Authorization header is not replayed to the new proxy
Updated packages:
  • curl-7.76.1-31.el9_6.1.tuxcare.els12.x86_64.rpm
    sha:6d52ed06d3e0eeed736dab04b73e70e4739aa34d95ff6c084c4a2c53db9519eb
  • curl-minimal-7.76.1-31.el9_6.1.tuxcare.els12.x86_64.rpm
    sha:fc121969333c451bb92433c061ce9127f8d6ded2da590feefb576a6ad1d6cf4f
  • libcurl-7.76.1-31.el9_6.1.tuxcare.els12.i686.rpm
    sha:2fb70c4c3ef10222baa5028231ae8d236fda9a8eb5885ce697048851decdcb77
  • libcurl-7.76.1-31.el9_6.1.tuxcare.els12.x86_64.rpm
    sha:fb0024e19fdd5d7f533317cb04c1a39e234a08aa5f3ac8a9f27049bb4065031e
  • libcurl-devel-7.76.1-31.el9_6.1.tuxcare.els12.i686.rpm
    sha:b9d04d4ad478459e57f89f0d4ea65d3d10820d4488ec71257d1b7fb3b164db3c
  • libcurl-devel-7.76.1-31.el9_6.1.tuxcare.els12.x86_64.rpm
    sha:9ca2eb365c67bc9b98e308caac200e9fe63aa777001c9c61c2f1bcb34feb55ab
  • libcurl-minimal-7.76.1-31.el9_6.1.tuxcare.els12.i686.rpm
    sha:4ab7f3be5895f3056b352151d3d3bcc00f8c184632865ca237a5d63a1229bbde
  • libcurl-minimal-7.76.1-31.el9_6.1.tuxcare.els12.x86_64.rpm
    sha:e238ad5103716ba238b66f735fb32c094acf08a3149f2b249aa05e380b21b55b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.