We have identified
CVE-2026-11586 affecting the bundled
libcurl.dll (version 8.20.0) within our
PostgreSQL 15.18 Windows installation. The vulnerability is reported by Nessus, and the fixed version is
libcurl 8.21.0 or later.
[tenable.com],
[curl.se] We are asking EDB to:
- Confirm whether a newer PostgreSQL 15.x installer is available that includes libcurl 8.21.0+.
- Advise on the supported remediation path for this vulnerability.
- Confirm whether a security update or hotfix is planned for PostgreSQL 15.
- Advise whether manually updating the bundled libcurl.dll is supported.
- Clarify whether the bundled libcurl component is actually used in a standard PostgreSQL 15.18 deployment.
Evidence provided:
- PostgreSQL version: 15.18
- libcurl version: 8.20.0
- File location:
C:\Program Files\PostgreSQL\15\bin\libcurl.dll
Dean Moore
Infrastructure Support Engineer (Mobile), Capita Intelligent Communications
AI & PO
07769 239517
7-11 Lower Oakham Way, Oakham Business Park, Mansfield, NG18 5BY

Capita plc | Registered in England and Wales | Registration no. 02081330
Registered office First Floor | 2 Kingdom St | Paddington | London | W2 6BD | www.capita.com
Confidential External - Data to be shared with caution.
This email is security checked and subject to the disclaimer on web-page: https://www.capita.com/email-disclaimer.aspx