RHSA-2026:29017HighCVSS 8.1

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
June 24, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (15)

📋 Description

CVE-2026-8286 — curl: curl: Insecure connection establishment due to TLS configuration mismatch CVE-2026-8924 — curl: curl: Cookie injection via malicious HTTP server using super cookies CVE-2026-8925 — curl: curl: Double-free vulnerability in SASL authentication CVE-2026-8926 — curl: curl: Information disclosure via incorrect .netrc password lookup CVE-2026-8927 — curl: Information disclosure due to uncleared proxy authentication state CVE-2026-8932 — libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse CVE-2026-9079 — libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials CVE-2026-9080 — libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback CVE-2026-9546 — libcurl: libcurl: Information disclosure due to persistent Referer header CVE-2026-9547 — curl: curl: Man-in-the-middle attack via SSH host key bypass CVE-2026-11352 — curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability CVE-2026-11564 — libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse CVE-2026-11586 — curl: curl: Denial of Service via WebSocket PING flood CVE-2026-11856 — curl: curl: Information disclosure via incorrect Digest authentication header reuse CVE-2026-12064 — curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP

🔗 References (20)