cbcvebase.
CVE-2026-8458
published 2026-07-03

CVE-2026-8458: libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different…

PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.54%
41.8th percentile
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.

Affected

100 ranges· showing 25
VendorProductVersion rangeFixed in
curlcurl7.43.0 – 7.43.0
curlcurl7.44.0 – 7.44.0
curlcurl7.45.0 – 7.45.0
curlcurl7.46.0 – 7.46.0
curlcurl7.47.0 – 7.47.0
curlcurl7.47.1 – 7.47.1
curlcurl7.48.0 – 7.48.0
curlcurl7.49.0 – 7.49.0
curlcurl7.49.1 – 7.49.1
curlcurl7.50.0 – 7.50.0
curlcurl7.50.1 – 7.50.1
curlcurl7.50.2 – 7.50.2
curlcurl7.50.3 – 7.50.3
curlcurl7.51.0 – 7.51.0
curlcurl7.52.0 – 7.52.0
curlcurl7.52.1 – 7.52.1
curlcurl7.53.0 – 7.53.0
curlcurl7.53.1 – 7.53.1
curlcurl7.54.0 – 7.54.0
curlcurl7.54.1 – 7.54.1
curlcurl7.55.0 – 7.55.0
curlcurl7.55.1 – 7.55.1
curlcurl7.56.0 – 7.56.0
curlcurl7.56.1 – 7.56.1
curlcurl7.57.0 – 7.57.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.