# cURL patched for 18 vulnerabilities in 8.21.0

Published: 2026-06-24 · Severity: medium
Canonical: https://vorant.io/reports/4058326a-2751-5225-9fc8-175b1b4028c8/curl-patched-for-18-vulnerabilities-in-8-21-0

> CERT-FR advises patching cURL and libcurl to version 8.21.0 to address 18 vulnerabilities enabling denial of service, information disclosure, and security policy bypass.

The French CERT has issued an advisory for multiple vulnerabilities discovered in cURL and libcurl affecting all versions prior to 8.21.0. The vendor released security bulletins on June 24, 2026, addressing 18 distinct CVE identifiers spanning issues that could enable remote denial of service attacks, unauthorized access to confidential data, and circumvention of security policies.

The vulnerability set includes CVE-2026-10536, CVE-2026-11352, CVE-2026-11564, CVE-2026-11586, CVE-2026-11856, CVE-2026-12064, CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8925, CVE-2026-8926, CVE-2026-8927, CVE-2026-8932, CVE-2026-9079, CVE-2026-9080, CVE-2026-9545, CVE-2026-9546, and CVE-2026-9547. Additionally, the advisory references CVE-2022-27782, CVE-2026-5545, and CVE-2026-7168.

Organizations using cURL or libcurl should prioritize upgrading to version 8.21.0 or later. Given cURL's ubiquity as a data transfer library embedded in countless applications, operating systems, and devices, the exposure surface is extensive across all sectors. Administrators should consult the vendor security bulletins for specific vulnerability details and apply patches according to their risk management procedures.

## Mentioned in this report

- Vulnerabilities: CVE-2022-27782, CVE-2026-10536, CVE-2026-11352, CVE-2026-11564, CVE-2026-11586, CVE-2026-11856, CVE-2026-12064, CVE-2026-5545, CVE-2026-7168, CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8925, CVE-2026-8926, CVE-2026-8927, CVE-2026-8932, CVE-2026-9079, CVE-2026-9080, CVE-2026-9545, CVE-2026-9546, CVE-2026-9547

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0797

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4058326a-2751-5225-9fc8-175b1b4028c8/curl-patched-for-18-vulnerabilities-in-8-21-0.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
