Notice USN-8820-1, published on September 24, 2026, says an update fixes vulnerabilities in curl. The reported issues include possible bypass of peer validation during LDAP authentication, flaws in HTTP/2 streams and TLS connection lifecycles, bypass of public-key pinning, exposure of information through cookies, and access to proxy credentials. Some flaws could cause denial of service or code execution. The notice associates the issues with CVE-2026-13608, CVE-2026-18924, CVE-2026-80229, CVE-2026-80230, CVE-2026-80255, CVE-2026-82209, and CVE-2026-8927.
The affected scope varies by flaw and release: the notice cites Ubuntu 16.04, 18.04, 20.04, 22.04, 24.04, and 26.04 LTS, with some vulnerabilities limited to specific releases. It also says an earlier fix for CVE-2026-8927 was incomplete on Ubuntu 16.04 LTS. Consult the original Ubuntu security notice and the CVE records to verify affected versions, fixed packages, and guidance for your environment. If using AI to analyze logs or plan an update, remove secrets and personal data and follow your organization’s policy.