Ubuntu patched ten holes in curl at once - the tool that fetches something in every script, container and CI pipeline. The ugliest one sends saved passwords to a server that simply returned a redirect. Advisory-level note: it doesn't claim active exploitation.
- USN-8525-1, 9 July 2026: ten CVEs in curl, from Ubuntu 14.04 LTS to 26.04 LTS.
- Credentials saved in .netrc can leak to a stranger's host on a redirect - without the user doing anything wrong.
- There's also a use-after-free over HTTP/2, a denial of service over HTTP/3, and a bypass of SSH host key verification. Ubuntu doesn't claim active exploitation.
You've stuffed it into a script, a container, a CI pipeline, every Dockerfile that fetches something off the network - and you don't even remember when. curl (a tool for downloading files) is everywhere because nobody installs it on purpose. It's just there. So a patch in curl isn't news about one product. It touches everything we've put into production.
Dead center is the scenario with .netrc. curl can send your credentials (username and password) to a completely different host just because the server returned a redirect. Nobody typed a wrong password. Nobody clicked a phishing link. The automation is just doing its job - and handing passwords to a stranger's server.
We're updating curl everywhere it exists - servers, container images, CI machines. Ten CVEs sounds scary, but by Ubuntu's own words none of them is being exploited. A patch, not a fire. And as always - if someone tells you something's being exploited, ask for the CVE.