we_are_coded.by CODE · The world, decoded
БГ
Ubuntu Security

Ten holes in curl: your passwords can travel to a stranger's server on a redirect

Ubuntu Security Notice USN-8525-1Security

Ubuntu patched ten holes in curl at once - the tool that fetches something in every script, container and CI pipeline. The ugliest one sends saved passwords to a server that simply returned a redirect. Advisory-level note: it doesn't claim active exploitation.

In short
  • USN-8525-1, 9 July 2026: ten CVEs in curl, from Ubuntu 14.04 LTS to 26.04 LTS.
  • Credentials saved in .netrc can leak to a stranger's host on a redirect - without the user doing anything wrong.
  • There's also a use-after-free over HTTP/2, a denial of service over HTTP/3, and a bypass of SSH host key verification. Ubuntu doesn't claim active exploitation.
Checked on10 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

You've stuffed it into a script, a container, a CI pipeline, every Dockerfile that fetches something off the network - and you don't even remember when. curl (a tool for downloading files) is everywhere because nobody installs it on purpose. It's just there. So a patch in curl isn't news about one product. It touches everything we've put into production.

The facts: USN-8525-1, published on 9 July 2026 by Ubuntu Security. Ten CVEs in curl, affected versions from Ubuntu 14.04 LTS (a long-term support version) to 26.04 LTS, including 25.10. Among the numbers: CVE-2024-11053, CVE-2024-8096, CVE-2026-5545, CVE-2026-7168, CVE-2026-11586, plus five more. The advisory doesn't report active exploitation.

Dead center is the scenario with .netrc. curl can send your credentials (username and password) to a completely different host just because the server returned a redirect. Nobody typed a wrong password. Nobody clicked a phishing link. The automation is just doing its job - and handing passwords to a stranger's server.

The automation doesn't check where it's being redirected. It just executes.

We're updating curl everywhere it exists - servers, container images, CI machines. Ten CVEs sounds scary, but by Ubuntu's own words none of them is being exploited. A patch, not a fire. And as always - if someone tells you something's being exploited, ask for the CVE.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Ubuntu Security Notice USN-8525-1
Original: https://wearecoded.com/en/articles/curl-usn-8525-ten-cves.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news