OPENSUSE-SU-2026:20031-1

Advisory lineage Upstream: 5 Downstream: 0
Published: 14 Jan 2026, 11:01
Last modified:23 Mar 2026, 04:54

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Jan 2026, 11:01
Published
Vulnerability first disclosed
23 Mar 2026, 04:54
Last Modified
Vulnerability information updated

Description

Security update for curl This update for curl fixes the following issues: This update for curl fixes the following issues: - CVE-2025-14017: broken TLS options for threaded LDAPS (bsc#1256105). - CVE-2025-14524: bearer token leak on cross-protocol redirect (bsc#1255731). - CVE-2025-14819: libssh global knownhost override (bsc#1255732). - CVE-2025-15079: libssh key passphrase bypass without agent set (bsc#1255733). - CVE-2025-15224: OpenSSL partial chain store policy bypass (bsc#1255734).

Affected Systems

  • opensusecurl&distro=openSUSE Leap 16.0

    < 8.14.1-160000.4.1

References (10)