Vulnerabilities in Libcurl 8.20.0 and older in the SiteMinder r12.9 Policy Server
search cancel

Vulnerabilities in Libcurl 8.20.0 and older in the SiteMinder r12.9 Policy Server

book

Article ID: 451429

calendar_today

Updated On:

Products

SITEMINDER

Issue/Introduction

The SiteMinder Policy Server bundles Libcurl binaries in the installation.  SiteMinder Policy Server 12.9 ships with LibCurl 8.12.1.0

KB 437711 (Archived) Delivered LibCurl 8.19.0

NOTE: This KB only applies to SiteMinder Policy Server r12.9.  For the 12.8.8.1 and older Policy Servers use KB 437690 Vulnerability in Libcurl 8.20.0 and older in the Siteminder Policy Server r12.8.8.1 and older

Environment

PRODUCT: Symantec SiteMinder

COMPONENT: Policy Server

VERSIONS: r12.9 (Only)

OPERATING SYSTEM: Any

Cause

The following CVE's impact LibCurl 8.12.1.0 - 8.20.0.  All CVE's are remediated with LibCurl 8.21.0

 

Common Vulnerability Enumeration (CVE)DESCRIPTION1st VERSION IMPACTEDLAST VERSION IMPACTEDREMEDIATED
CVE-2026-12064proto-default skips SSH verification7.81.08.20.08.21.0
CVE-2026-11856cross-origin Digest auth state leak7.10.68.20.08.21.0
CVE-2026-10536HTTP/2 stream-dependency tree UAF7.88.08.20.08.21.0
CVE-2026-9547SSH improper host validation7.69.08.20.08.21.0
CVE-2026-9545exposing HTTP/3 early data8.11.08.20.08.21.0
CVE-2026-9079stale proxy password leak8.8.08.20.08.21.0
CVE-2026-8932incomplete mTLS config matching in conn reuse7.78.20.08.21.0
CVE-2026-8927env-set cross-proxy Digest auth state leak7.12.08.20.08.21.0
CVE-2026-8926password leak with netrc and user in URL8.11.18.20.08.21.0
CVE-2026-8924trailing dot domain super cookie7.46.08.20.08.21.0
CVE-2026-8458wrong reuse for different services7.43.08.20.08.21.0
CVE-2026-8286wrong STARTTLS connection reuse7.30.08.20.08.21.0
CVE-2026-7168cross-proxy Digest auth state leak7.12.08.19.08.20.0 - 8.21.0
CVE-2026-6429netrc credential leak with reused proxy connection7.14.08.19.08.20.0 - 8.21.0
CVE-2026-6276stale custom cookie host causes cookie leak7.71.08.19.08.20.0 - 8.21.0
CVE-2026-6253proxy credentials leak over redirect-to proxy7.14.18.19.08.20.0 - 8.21.0
CVE-2026-5773wrong reuse of SMB connection7.40.08.19.08.20.0 - 8.21.0
CVE-2026-5545wrong reuse of HTTP Negotiate connection7.10.68.19.08.20.0 - 8.21.0
CVE-2026-4873connection reuse ignores TLS requirement7.20.08.19.08.20.0 - 8.21.0
CVE-2026-3784wrong proxy connection reuse with credentials7.78.18.08.19.0 - 8.21.0
CVE-2026-3783token leak with redirect and netrc7.33.08.18.08.19.0 - 8.21.0
CVE-2026-1965bad reuse of HTTP Negotiate connection7.10.68.18.08.19.0 - 8.21.0
CVE-2025-15224libssh key passphrase bypass without agent set7.58.08.17.08.18.0 - 8.21.0
CVE-2025-15079libssh global known_hosts override7.58.08.17.08.18.0 - 8.21.0
CVE-2025-14819OpenSSL partial chain store policy bypass7.87.08.17.08.18.0 - 8.21.0
CVE-2025-14524bearer token leak on cross-protocol redirect7.33.08.17.08.18.0 - 8.21.0
CVE-2025-14017broken TLS options for threaded LDAPS7.17.08.17.08.18.0 - 8.21.0
CVE-2025-13034No QUIC certificate pinning with GnuTLS8.8.08.17.08.18.0 - 8.21.0
CVE-2025-10966missing SFTP host verification with wolfSSH7.69.08.16.08.17.0 - 8.21.0
CVE-2025-10148predictable WebSocket mask8.11.08.15.08.16.0 - 8.21.0
CVE-2025-5025No QUIC certificate pinning with wolfSSL8.5.08.13.08.14.0 - 8.21.0
CVE-2025-4947QUIC certificate check skip with wolfSSL8.8.08.13.08.14.0 - 8.21.0

Resolution

Using this KB you can upgrade LibCurl on the r12.9 SiteMinder Policy Server to LibCurl 8.21.0.  LibCurl 8.21.0 has been attached to this KB.

NOTE: This KB only applies to SiteMinder Policy Server r12.9.  For the 12.8.8.1 and older Policy Servers use KB 437690 Vulnerability in Libcurl 8.20.0 and older in the Siteminder Policy Server r12.8.8.1 and older

Upgrade SiteMinder r12.9 to LibCurl 8.21.0

LINUX 

1) Download 'libcurl8210_linux_12.9GA.zip' to the SiteMinder Policy Server

2) Decompress 'libcurl8210_linux_12.9GA.zip'

Contents:

libcurl.so
libcurl.so.4
libcurl.so.4.8.0

3) Stop the SiteMinder Policy Server

4) Backup and Delete, or Rename the following files:

/<Install_Dir>/CA/siteminder/lib/libcurl.so.4.8.0
/<Install_Dir>/CA/siteminder/lib/libcurl.so.4
/<Install_Dir>/CA/siteminder/lib/libcurl.so

5) Copy the following files from 'libcurl8210_linux_12.9GA.zip' into the '/<Install_Dir>/CA/siteminder/lib/' directory.

libcurl.so
libcurl.so.4
libcurl.so.4.8.0

6) Start the SiteMinder Policy Server

WINDOWS

1) Download 'libcurl_8210_win64_12.9GA.zip' to the SiteMinder Policy Server

2) Decompress 'libcurl_8210_win64_12.9GA.zip'

3) Stop the SiteMinder Policy Server

4) Backup and Delete, or Rename the following files:

<Install_Dir>\CA\siteminder\bin\libcurl.dll

5) Copy the following files from 'libcurl_8210_win64_12.9GA.zip' into the '<Install_Dir>\CA\siteminder\bin\' directory.

libcurl.dll

6) Start the SiteMinder Policy Server

Additional Information

curl and libcurl vulnerabilities

KB 437690 Vulnerability in Libcurl 8.10.0 and older in the Siteminder Policy Server r12.8.8.1 and older

Libcurl 8.21.0 Remediate the following CVE's:

CVE-2026-12064
CVE-2026-11856
CVE-2026-10536
CVE-2026-9547
CVE-2026-9545
CVE-2026-9079
CVE-2026-8932
CVE-2026-8927
CVE-2026-8926
CVE-2026-8924
CVE-2026-8458
CVE-2026-8286
CVE-2026-7168
CVE-2026-6429
CVE-2026-6276
CVE-2026-6253
CVE-2026-5773
CVE-2026-5545
CVE-2026-4873
CVE-2026-3784
CVE-2026-3783
CVE-2026-1965
CVE-2025-15224
CVE-2025-15079
CVE-2025-14819
CVE-2025-14524
CVE-2025-14017
CVE-2025-13034
CVE-2025-10966
CVE-2025-10148
CVE-2025-5025
CVE-2025-4947

 

Attachments

libcurl8210_linux_12.9GA.zip get_app
libcurl_8210_win64_12.9GA.zip get_app