cURL patched for 18 vulnerabilities in 8.21.0
CERT-FR advises patching cURL and libcurl to version 8.21.0 to address 18 vulnerabilities enabling denial of service, information disclosure, and security policy bypass.
The French CERT has issued an advisory for multiple vulnerabilities discovered in cURL and libcurl affecting all versions prior to 8.21.0. The vendor released security bulletins on June 24, 2026, addressing 18 distinct CVE identifiers spanning issues that could enable remote denial of service attacks, unauthorized access to confidential data, and circumvention of security policies.
The vulnerability set includes CVE-2026-10536, CVE-2026-11352, CVE-2026-11564, CVE-2026-11586, CVE-2026-11856, CVE-2026-12064, CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8925, CVE-2026-8926, CVE-2026-8927, CVE-2026-8932, CVE-2026-9079, CVE-2026-9080, CVE-2026-9545, CVE-2026-9546, and CVE-2026-9547. Additionally, the advisory references CVE-2022-27782, CVE-2026-5545, and CVE-2026-7168.
Organizations using cURL or libcurl should prioritize upgrading to version 8.21.0 or later. Given cURL's ubiquity as a data transfer library embedded in countless applications, operating systems, and devices, the exposure surface is extensive across all sectors. Administrators should consult the vendor security bulletins for specific vulnerability details and apply patches according to their risk management procedures.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0797
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free