We have identified CVE-2026-11586 affecting the bundled libcurl.dll (version 8.20.0) within our PostgreSQL 15.18 Windows installation. The vulnerability is reported by Nessus, and the fixed version is libcurl 8.21.0 or later. [tenable.com]<https://www.tenable.com/plugins/nessus/326239>, [curl.se]<https://curl.se/docs/CVE-2026-11586.html> We are asking EDB to:
* Confirm whether a newer PostgreSQL 15.x installer is available that includes libcurl 8.21.0+. * Advise on the supported remediation path for this vulnerability. * Confirm whether a security update or hotfix is planned for PostgreSQL 15. * Advise whether manually updating the bundled libcurl.dll is supported. * Clarify whether the bundled libcurl component is actually used in a standard PostgreSQL 15.18 deployment. Evidence provided: * PostgreSQL version: 15.18 * libcurl version: 8.20.0 * File location: C:\Program Files\PostgreSQL\15\bin\libcurl.dll Dean Moore Infrastructure Support Engineer (Mobile), Capita Intelligent Communications AI & PO 07769 239517 7-11 Lower Oakham Way, Oakham Business Park, Mansfield, NG18 5BY [cid:ef859559-8d72-4875-b1e1-14d72d1a5202] Capita plc | Registered in England and Wales | Registration no. 02081330 Registered office First Floor | 2 Kingdom St | Paddington | London | W2 6BD | www.capita.com<http://www.capita.com/> Confidential External - Data to be shared with caution. This email is security checked and subject to the disclaimer on web-page: https://www.capita.com/email-disclaimer.aspx
