This update for curl fixes the following issues:
* CVE-2026-1965: bad reuse of HTTP Negotiate connection (bsc#1259362).
* CVE-2026-3783: token leak with redirect and netrc (bsc#1259363).
* CVE-2026-3784: wrong proxy connection reuse with credentials (bsc#1259364).
* CVE-2026-3805: use after free in SMB connection reuse (bsc#1259365).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-911=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-911=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-911=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-911=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-911=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-911=1 SUSE-SLE-Product-
SLES_SAP-15-SP4-2026-911=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zy...
Read the Full Advisory* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* libcurl4-debuginfo-8.14.1-150400.5.80.1
* libcurl4-8.14.1-150400.5.80.1
* curl-debuginfo-8.14.1-150400.5.80.1
* curl-8.14.1-150400.5.80.1
* curl-debugsource-8.14.1-150400.5.80.1
* libcurl-devel-8.14.1-150400.5.80.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64)
* libcurl4-32bit-debuginfo-8.14.1-150400.5.80.1
* libcurl4-32bit-8.14.1-150400.5.80.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* libcurl4-debuginfo-8.14.1-150400.5.80.1
* libcurl4-8.14.1-150400.5.80.1
* curl-debuginfo-8.14.1-150400.5.80.1
* curl-8.14.1-150400.5.80.1
* curl-debugsource-8.14.1-150400.5.80.1
* libcurl-devel-8.14.1-150400.5.80.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)
* libcurl4-32bit-debuginfo-8.14.1-150400.5.80.1
* libcurl4-32bit-8.14.1-150400.5.80.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
*...
Read the Full Advisory* bsc#1259362
* bsc#1259363
* bsc#1259364
* bsc#1259365
## References:
* https://www.suse.com/security/cve/CVE-2026-1965.html
* https://www.suse.com/security/cve/CVE-2026-3783.html
* https://www.suse.com/security/cve/CVE-2026-3784.html
* https://www.suse.com/security/cve/CVE-2026-3805.html
* https://bugzilla.suse.com/show_bug.cgi?id=1259362
* https://bugzilla.suse.com/show_bug.cgi?id=1259363
* https://bugzilla.suse.com/show_bug.cgi?id=1259364
* https://bugzilla.suse.com/show_bug.cgi?id=1259365
Get the latest Linux and open source security news straight to your inbox.