EulerOS 2.0 SP10 : curl (EulerOS-SA-2026-3687)

critical Nessus Plugin ID 347115

Synopsis

The remote EulerOS host is missing multiple security updates.

Description

According to the versions of the curl packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.(CVE-2026-8286)

['Hello friends,', 'CVE-2026-8286: wrong STARTTLS connection reuse (LOW)', 'CVE-2026-8458: wrong reuse for different services (LOW)', 'CVE-2026-8924: traling dot domain super cookie (LOW)', 'CVE-2026-8925: SASL double-free (MEDIUM)', 'CVE-2026-8926: password leak with netrc and user in URL (LOW)', 'CVE-2026-8927:
env-set cross-proxy Digest auth state leak (MEDIUM)', 'CVE-2026-8932: incomplete mTLS config matching in conn reuse (LOW)', 'CVE-2026-9079: stale proxy password leak (MEDIUM)', 'CVE-2026-9080: UAF after pause in socket callback (LOW)', 'CVE-2026-9545: exposing HTTP/3 early data (LOW)', 'CVE-2026-9546: sending old referer (LOW)', 'CVE-2026-9547: SSH improper host validation (LOW)', 'CVE-2026-10536: HTTP/2 stream- dependency tree UAF (LOW)', 'CVE-2026-11352: QUIC zero-length UDP datagrams busy-loop (LOW)', 'CVE-2026-11564: Native CA trust persist (LOW)', 'CVE-2026-11586: WS Auto-PONG memory exhaustion (LOW)', 'CVE-2026-11856: cross-origin Digest auth state leak (MEDIUM)', 'CVE-2026-12064: proto-default skips SSH verification (LOW)', '--\n\n / daniel.haxx.se ||'](CVE-2026-8924)

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.(CVE-2026-8927)

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.(CVE-2026-9547)

Tenable has extracted the preceding description block directly from the EulerOS curl security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected curl packages.

See Also

http://www.nessus.org/u?6179d7be

Plugin Details

Severity: Critical

ID: 347115

File Name: EulerOS_SA-2026-3687.nasl

Version: 1.1

Type: Local

Published: 9/18/2026

Updated: 9/18/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.7

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-9547

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-8927

Vulnerability Information

CPE: cpe:/o:huawei:euleros:2.0, p-cpe:/a:huawei:euleros:curl-help, p-cpe:/a:huawei:euleros:curl, p-cpe:/a:huawei:euleros:libcurl-devel, p-cpe:/a:huawei:euleros:libcurl

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/sp

Excluded KB Items: Host/EulerOS/uvp_version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/16/2026

Vulnerability Publication Date: 6/25/2026

Reference Information

CVE: CVE-2026-8286, CVE-2026-8924, CVE-2026-8927, CVE-2026-9547

IAVA: 2026-A-0627-S