CVE-2026-11586

From: "Moore, Dean (Capita)" <Dean(dot)Moore(at)capita(dot)com>
To: "pgsql-general(at)postgresql(dot)org" <pgsql-general(at)postgresql(dot)org>
Subject: CVE-2026-11586
Date: 2026-07-27 13:52:48
Message-ID: LOBP265MB8979BA0B5B2C7526676AB7EBE1CC2@LOBP265MB8979.GBRP265.PROD.OUTLOOK.COM
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-general

We have identified CVE-2026-11586 affecting the bundled libcurl.dll (version 8.20.0) within our PostgreSQL 15.18 Windows installation. The vulnerability is reported by Nessus, and the fixed version is libcurl 8.21.0 or later. [tenable.com]<https://www.tenable.com/plugins/nessus/326239>, [curl.se]<https://curl.se/docs/CVE-2026-11586.html>
We are asking EDB to:

* Confirm whether a newer PostgreSQL 15.x installer is available that includes libcurl 8.21.0+.
* Advise on the supported remediation path for this vulnerability.
* Confirm whether a security update or hotfix is planned for PostgreSQL 15.
* Advise whether manually updating the bundled libcurl.dll is supported.
* Clarify whether the bundled libcurl component is actually used in a standard PostgreSQL 15.18 deployment.

Evidence provided:

* PostgreSQL version: 15.18
* libcurl version: 8.20.0
* File location: C:\Program Files\PostgreSQL\15\bin\libcurl.dll

Dean Moore
Infrastructure Support Engineer (Mobile), Capita Intelligent Communications
AI & PO

07769 239517
7-11 Lower Oakham Way, Oakham Business Park, Mansfield, NG18 5BY

[cid:ef859559-8d72-4875-b1e1-14d72d1a5202]
Capita plc | Registered in England and Wales | Registration no. 02081330
Registered office First Floor | 2 Kingdom St | Paddington | London | W2 6BD | www.capita.com<http://www.capita.com/>

Confidential External - Data to be shared with caution.
This email is security checked and subject to the disclaimer on web-page: https://www.capita.com/email-disclaimer.aspx

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Adrian Klaver 2026-07-27 20:04:19 Re: CVE-2026-11586
Previous Message Vincent Veyron 2026-07-25 19:41:13 Re: Check for Updates?