CVE-2026-11586 - Mailing list pgsql-general

From Moore, Dean (Capita)
Subject CVE-2026-11586
Date
Msg-id LOBP265MB8979BA0B5B2C7526676AB7EBE1CC2@LOBP265MB8979.GBRP265.PROD.OUTLOOK.COM
Whole thread
List pgsql-general
We have identified CVE-2026-11586 affecting the bundled libcurl.dll (version 8.20.0) within our PostgreSQL 15.18 Windows installation. The vulnerability is reported by Nessus, and the fixed version is libcurl 8.21.0 or later. [tenable.com], [curl.se]
We are asking EDB to:
  • Confirm whether a newer PostgreSQL 15.x installer is available that includes libcurl 8.21.0+.
  • Advise on the supported remediation path for this vulnerability.
  • Confirm whether a security update or hotfix is planned for PostgreSQL 15.
  • Advise whether manually updating the bundled libcurl.dll is supported.
  • Clarify whether the bundled libcurl component is actually used in a standard PostgreSQL 15.18 deployment.
Evidence provided:
  • PostgreSQL version: 15.18
  • libcurl version: 8.20.0
  • File location: C:\Program Files\PostgreSQL\15\bin\libcurl.dll


Dean Moore
Infrastructure Support Engineer (Mobile), Capita Intelligent Communications
AI & PO

07769 239517
7-11 Lower Oakham Way, Oakham Business Park, Mansfield, NG18 5BY


Capita plc | Registered in England and Wales | Registration no. 02081330
Registered office First Floor | 2 Kingdom St | Paddington | London | W2 6BD |
www.capita.com



Confidential External - Data to be shared with caution.
This email is security checked and subject to the disclaimer on web-page: https://www.capita.com/email-disclaimer.aspx
Attachment

pgsql-general by date:

Previous
From: aadish ajay
Date:
Subject: Feedback wanted: a framework where Postgres is the entire backend (no ORM/API layer)
Next
From: Simon Connah
Date:
Subject: Re: Check for Updates?