CVE-2026-12064

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP5 security update

Beschreibung

Wenn ein Benutzer `curl` mit einem URLs ohne Schema in Kombination mit `--proto-default sftp` (oder scp) aufruft, tritt eine Unterbrechung zwischen der Werkzeugebene und libcurl auf. Die Werkzeugebene schließt das URL-Schema fälschlicherweise aus, wodurch die Initialisierung kritischer SSH-Sicherheitsoptionen wie CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 und CURLOPT_SSH_KNOWNHOSTS umgangen wird. Im Gegensatz dazu respektiert der libcurl-Laufzeitumgebung erfolgreich CURLOPT_DEFAULT_PROTOCOL und stellt die Verbindung über SFTP/SCP her, wie angegeben. Da die Werkzeugebene die Sicherheitskonfiguration übersprungen hat, werden diese SSH-Hostüberprüfungs-Optionen stillschweigend ausgelassen, wodurch curl eine Verbindung zu einem nicht verifizierten SSH-Remotehost ohne Fehlermeldung herstellt.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.4
Quelle: nvd-v3
33.4 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-19 13:28 UTC

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-07-06 19:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
    • Reference: https://hackerone.com/reports/3797526
    • SSVC: {"id":"CVE-2026-12064","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalI…
  2. New CVE Received2026-07-03 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
    • Affected: curl
    • Description: When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.
    • Reference: https://curl.se/docs/CVE-2026-12064.html
    • Reference: https://curl.se/docs/CVE-2026-12064.json

Betroffene Betriebssysteme

  • linux

    ubuntu / curlbionic

  • linux

    ubuntu / curlfocal

  • linux

    ubuntu / curlnoble

  • linux

    ubuntu / curlquesting

  • linux

    ubuntu / curlresolute

  • linux

    ubuntu / curltrusty

  • linux

    ubuntu / curlxenial

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    http_server2.4.0 – 2.4.68

  • Apple

    iOS18.7.10

  • Apple

    iOS26.6.1

  • Apple

    iPadOS18.7.10

  • Apple

    iPadOS26.6.1

  • Apple

    macOSTahoe 26.6.2

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.55

  • bitnami

    apache

  • haxx

    curl7.30.0 – 8.21.0

  • haxx

    curl7.46.0 – 8.20.0

  • haxx

    curl7.46.0 – 8.21.0

  • haxx

    curl7.69.0 – 8.21.0

  • haxx

    curl8.11.0 – 8.21.0

  • Hitachi Energy

    RTU500< 13.9.1

    gefixt in 13.9.1

  • Splunk

    Splunk Enterprise< 10.0.9

    gefixt in 10.0.9

  • Splunk

    Splunk Enterprise< 10.2.6

    gefixt in 10.2.6

  • Splunk

    Splunk Enterprise< 10.4.2

    gefixt in 10.4.2

  • Splunk

    Splunk Enterprise< 9.4.14

    gefixt in 9.4.14

Quellen & Referenzen

Verknüpfte CVEs

5 weitere CVEs anzeigen
IDCVE-2026-12064