Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Release curl-8.12.1-4.el10_2.3 ALSA-2026:55450

Open
#3,290 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Active
Tech stack
linux
Domain
release, security

Research direction

Start from the issue body: it lists the curl/libcurl build version, architectures, and CVEs for the security update. Read the repository's release/update process before changing anything, because no files or tests are named here. Done means the curl-8.12.1-4.el10_2.3 update is released or tracked for all listed affected packages.

Written by the indexing model from the issue text.

Description

curl security update
Severity: Important
Description
The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

  • curl: libcurl: Improper certificate validation due to cached TLS settings reuse (CVE-2025-14819)
  • curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication (CVE-2026-1965)
  • curl: curl: Unauthorized access due to improper HTTP proxy connection reuse (CVE-2026-3784)
  • curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect (CVE-2026-3783)
  • curl: curl: Man-in-the-middle attack via SSH host key bypass (CVE-2026-9547)
  • curl: curl: Insecure connection establishment due to TLS configuration mismatch (CVE-2026-8286)
  • curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP (CVE-2026-12064)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected packages:
curl-8.12.1-4.el10_2.3.x86_64
libcurl-8.12.1-4.el10_2.3.x86_64
libcurl-devel-8.12.1-4.el10_2.3.x86_64
libcurl-minimal-8.12.1-4.el10_2.3.x86_64
curl-8.12.1-4.el10_2.3.s390x
libcurl-8.12.1-4.el10_2.3.s390x
libcurl-devel-8.12.1-4.el10_2.3.s390x
libcurl-minimal-8.12.1-4.el10_2.3.s390x
curl-8.12.1-4.el10_2.3.ppc64le
libcurl-8.12.1-4.el10_2.3.ppc64le
libcurl-devel-8.12.1-4.el10_2.3.ppc64le
libcurl-minimal-8.12.1-4.el10_2.3.ppc64le
curl-8.12.1-4.el10_2.3.aarch64
libcurl-8.12.1-4.el10_2.3.aarch64
libcurl-devel-8.12.1-4.el10_2.3.aarch64
libcurl-minimal-8.12.1-4.el10_2.3.aarch64
curl-8.12.1-4.el10_2.3.x86_64_v2
libcurl-8.12.1-4.el10_2.3.x86_64_v2
libcurl-devel-8.12.1-4.el10_2.3.x86_64_v2
libcurl-minimal-8.12.1-4.el10_2.3.x86_64_v2

Dominant language
No language data
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from AlmaLinux/updates

All issues in AlmaLinux/updates

Similar issues

More Release issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.