Re: CVE-2026-11586

From: Adrian Klaver <adrian(dot)klaver(at)aklaver(dot)com>
To: "Moore, Dean (Capita)" <Dean(dot)Moore(at)capita(dot)com>, "pgsql-general(at)postgresql(dot)org" <pgsql-general(at)postgresql(dot)org>
Subject: Re: CVE-2026-11586
Date: 2026-07-27 20:04:19
Message-ID: f7b7ac26-0a04-4cad-aef9-7cc6063637a3@aklaver.com
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-general

On 7/27/26 6:52 AM, Moore, Dean (Capita) wrote:
> We have identified *CVE-2026-11586* affecting the bundled *libcurl.dll
> (version 8.20.0)* within our *PostgreSQL 15.18* Windows installation.
> The vulnerability is reported by Nessus, and the fixed version is
> *libcurl 8.21.0 or later*. [tenable.com] <https://www.tenable.com/
> plugins/nessus/326239>, [curl.se] <https://curl.se/docs/CVE-2026-11586.html>
> We are asking EDB to:

The Postgres project is responsible for the source code,
installers/packaging is done by third parties.

You should file an issue here:

https://github.com/EnterpriseDB/edb-installers/issues

> *Dean Moore
> *Infrastructure Support Engineer (Mobile), Capita Intelligent Communications
> AI & PO
>
> 07769 239517
> 7-11 Lower Oakham Way, Oakham Business Park, Mansfield, NG18 5BY
>
>
> Capita plc | Registered in England and Wales | Registration no. 02081330
> Registered office First Floor | 2 Kingdom St | Paddington | London | W2
> 6BD | _www.capita.com_ <http://www.capita.com/>
>
>
>
> Confidential External - Data to be shared with caution.
> This email is security checked and subject to the disclaimer on web-
> page: https://www.capita.com/email-disclaimer.aspx

--
Adrian Klaver
adrian(dot)klaver(at)aklaver(dot)com

In response to

Browse pgsql-general by date

  From Date Subject
Next Message pgmis 2026-07-27 20:21:55 PG19: guidance on temporal tables use for auditable link entities
Previous Message Moore, Dean (Capita) 2026-07-27 13:52:48 CVE-2026-11586