CVE-2026-8286
published 2026-07-03CVE-2026-8286: A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS…
PriorityP347high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.52%
40.8th percentile
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.
Affected
119 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 7.30.0 – 7.30.0 | — |
| curl | curl | 7.31.0 – 7.31.0 | — |
| curl | curl | 7.32.0 – 7.32.0 | — |
| curl | curl | 7.33.0 – 7.33.0 | — |
| curl | curl | 7.34.0 – 7.34.0 | — |
| curl | curl | 7.35.0 – 7.35.0 | — |
| curl | curl | 7.36.0 – 7.36.0 | — |
| curl | curl | 7.37.0 – 7.37.0 | — |
| curl | curl | 7.37.1 – 7.37.1 | — |
| curl | curl | 7.38.0 – 7.38.0 | — |
| curl | curl | 7.39.0 – 7.39.0 | — |
| curl | curl | 7.40.0 – 7.40.0 | — |
| curl | curl | 7.41.0 – 7.41.0 | — |
| curl | curl | 7.42.0 – 7.42.0 | — |
| curl | curl | 7.42.1 – 7.42.1 | — |
| curl | curl | 7.43.0 – 7.43.0 | — |
| curl | curl | 7.44.0 – 7.44.0 | — |
| curl | curl | 7.45.0 – 7.45.0 | — |
| curl | curl | 7.46.0 – 7.46.0 | — |
| curl | curl | 7.47.0 – 7.47.0 | — |
| curl | curl | 7.47.1 – 7.47.1 | — |
| curl | curl | 7.48.0 – 7.48.0 | — |
| curl | curl | 7.49.0 – 7.49.0 | — |
| curl | curl | 7.49.1 – 7.49.1 | — |
| curl | curl | 7.50.0 – 7.50.0 | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
ghsa_unreviewed·2026-07-03
CVE-2026-8286 A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.
Red Hat
curl: curl: Insecure connection establishment due to TLS configuration mismatch
vendor_redhat·2026-07-03·CVSS 8.1
CVE-2026-8286 [HIGH] CWE-295 curl: curl: Insecure connection establishment due to TLS configuration mismatch
curl: curl: Insecure connection establishment due to TLS configuration mismatch
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.
A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established.
Statement: This is an Important flaw as `curl` may establish an insecure connection when attempting to upgrade a transfer with STARTTLS, potentially reusing an existi
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-06-30
CVE-2026-8286 curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Andrew Nesbitt discovered that curl could reuse an existing live
connection during STARTTLS-based connection upgrades even when the TLS
configuration did not match. A remote attacker could possibly use this
issue to cause curl to use an unintended TLS configuration.
(CVE-2026-8286)
Muhamad Arga Reksapati discovered that curl incorrectly reused
connections for Negotiate-authenticated requests when different services
were involved. A remote attacker could possibly use this issue to access
resources authenticated for another service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458)
It was discovered that curl i
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-8286 curl: curl: Insecure connection establishment due to TLS configuration mismatch [fedora-all]
bugzilla·2026-07-06·CVSS 8.1
CVE-2026-8286 [HIGH] CVE-2026-8286 curl: curl: Insecure connection establishment due to TLS configuration mismatch [fedora-all]
CVE-2026-8286 curl: curl: Insecure connection establishment due to TLS configuration mismatch [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.
Bugzilla
CVE-2026-8286 rpi-imager: curl: Insecure connection establishment due to TLS configuration mismatch [fedora-all]
bugzilla·2026-07-06·CVSS 8.1
CVE-2026-8286 [HIGH] CVE-2026-8286 rpi-imager: curl: Insecure connection establishment due to TLS configuration mismatch [fedora-all]
CVE-2026-8286 rpi-imager: curl: Insecure connection establishment due to TLS configuration mismatch [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.
Bugzilla
CVE-2026-8286 mingw-curl: curl: Insecure connection establishment due to TLS configuration mismatch [fedora-all]
bugzilla·2026-07-06·CVSS 8.1
CVE-2026-8286 [HIGH] CVE-2026-8286 mingw-curl: curl: Insecure connection establishment due to TLS configuration mismatch [fedora-all]
CVE-2026-8286 mingw-curl: curl: Insecure connection establishment due to TLS configuration mismatch [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.
Bugzilla
CVE-2026-8286 curl: curl: Insecure connection establishment due to TLS configuration mismatch
bugzilla·2026-07-03·CVSS 8.1
CVE-2026-8286 [HIGH] CVE-2026-8286 curl: curl: Insecure connection establishment due to TLS configuration mismatch
CVE-2026-8286 curl: curl: Insecure connection establishment due to TLS configuration mismatch
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.
2026-07-03
Published