CVE-2026-8458
published 2026-07-03CVE-2026-8458: libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.54%
44.0th percentile
libcurl might in some circumstances reuse the wrong connection when asked to
do Negotiate-authenticated ones, even when they are set to use different
'services'.
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a request that was issued by an application could
wrongfully reuse an existing connection to the same server that was
authenticated using different services.
Affected
104 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 7.43.0 – 7.43.0 | — |
| curl | curl | 7.44.0 – 7.44.0 | — |
| curl | curl | 7.45.0 – 7.45.0 | — |
| curl | curl | 7.46.0 – 7.46.0 | — |
| curl | curl | 7.47.0 – 7.47.0 | — |
| curl | curl | 7.47.1 – 7.47.1 | — |
| curl | curl | 7.48.0 – 7.48.0 | — |
| curl | curl | 7.49.0 – 7.49.0 | — |
| curl | curl | 7.49.1 – 7.49.1 | — |
| curl | curl | 7.50.0 – 7.50.0 | — |
| curl | curl | 7.50.1 – 7.50.1 | — |
| curl | curl | 7.50.2 – 7.50.2 | — |
| curl | curl | 7.50.3 – 7.50.3 | — |
| curl | curl | 7.51.0 – 7.51.0 | — |
| curl | curl | 7.52.0 – 7.52.0 | — |
| curl | curl | 7.52.1 – 7.52.1 | — |
| curl | curl | 7.53.0 – 7.53.0 | — |
| curl | curl | 7.53.1 – 7.53.1 | — |
| curl | curl | 7.54.0 – 7.54.0 | — |
| curl | curl | 7.54.1 – 7.54.1 | — |
| curl | curl | 7.55.0 – 7.55.0 | — |
| curl | curl | 7.55.1 – 7.55.1 | — |
| curl | curl | 7.56.0 – 7.56.0 | — |
| curl | curl | 7.56.1 – 7.56.1 | — |
| curl | curl | 7.57.0 – 7.57.0 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'.
ghsa_unreviewed·2026-07-03
CVE-2026-8458 libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'.
libcurl might in some circumstances reuse the wrong connection when asked to
do Negotiate-authenticated ones, even when they are set to use different
'services'.
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a request that was issued by an application could
wrongfully reuse an existing connection to the same server that was
authenticated using different services.
Red Hat
curl: libcurl: Unauthorized connection reuse due to a logical error
vendor_redhat·2026-07-03·CVSS 6.5
CVE-2026-8458 [MEDIUM] CWE-305 curl: libcurl: Unauthorized connection reuse due to a logical error
curl: libcurl: Unauthorized connection reuse due to a logical error
libcurl might in some circumstances reuse the wrong connection when asked to
do Negotiate-authenticated ones, even when they are set to use different
'services'.
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a request that was issued by an application could
wrongfully reuse an existing connection to the same server that was
authenticated using different services.
A flaw was found in libcurl. A logical error in the connection pooling mechanism may cause libcurl to reuse an authenticated connection for an unintended service. This could allow an applic
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-06-30
CVE-2026-8286 curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Andrew Nesbitt discovered that curl could reuse an existing live
connection during STARTTLS-based connection upgrades even when the TLS
configuration did not match. A remote attacker could possibly use this
issue to cause curl to use an unintended TLS configuration.
(CVE-2026-8286)
Muhamad Arga Reksapati discovered that curl incorrectly reused
connections for Negotiate-authenticated requests when different services
were involved. A remote attacker could possibly use this issue to access
resources authenticated for another service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458)
It was discovered that curl i
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-8458 curl: libcurl: Unauthorized connection reuse due to a logical error [fedora-all]
bugzilla·2026-08-05·CVSS 6.5
CVE-2026-8458 [MEDIUM] CVE-2026-8458 curl: libcurl: Unauthorized connection reuse due to a logical error [fedora-all]
CVE-2026-8458 curl: libcurl: Unauthorized connection reuse due to a logical error [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl might in some circumstances reuse the wrong connection when asked to
do Negotiate-authenticated ones, even when they are set to use different
'services'.
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a request that was issued by an application could
wrongfully reuse an existing connection to t
Bugzilla
CVE-2026-8458 rpi-imager: libcurl: Unauthorized connection reuse due to a logical error [fedora-all]
bugzilla·2026-08-05·CVSS 6.5
CVE-2026-8458 [MEDIUM] CVE-2026-8458 rpi-imager: libcurl: Unauthorized connection reuse due to a logical error [fedora-all]
CVE-2026-8458 rpi-imager: libcurl: Unauthorized connection reuse due to a logical error [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl might in some circumstances reuse the wrong connection when asked to
do Negotiate-authenticated ones, even when they are set to use different
'services'.
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a request that was issued by an application could
wrongfully reuse an existing connectio
Bugzilla
CVE-2026-8458 davix: libcurl: Unauthorized connection reuse due to a logical error [epel-all]
bugzilla·2026-08-05·CVSS 6.5
CVE-2026-8458 [MEDIUM] CVE-2026-8458 davix: libcurl: Unauthorized connection reuse due to a logical error [epel-all]
CVE-2026-8458 davix: libcurl: Unauthorized connection reuse due to a logical error [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl might in some circumstances reuse the wrong connection when asked to
do Negotiate-authenticated ones, even when they are set to use different
'services'.
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a request that was issued by an application could
wrongfully reuse an existing connection to th
Bugzilla
CVE-2026-8458 mingw-curl: libcurl: Unauthorized connection reuse due to a logical error [fedora-all]
bugzilla·2026-08-05·CVSS 6.5
CVE-2026-8458 [MEDIUM] CVE-2026-8458 mingw-curl: libcurl: Unauthorized connection reuse due to a logical error [fedora-all]
CVE-2026-8458 mingw-curl: libcurl: Unauthorized connection reuse due to a logical error [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl might in some circumstances reuse the wrong connection when asked to
do Negotiate-authenticated ones, even when they are set to use different
'services'.
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a request that was issued by an application could
wrongfully reuse an existing connectio
Bugzilla
CVE-2026-8458 curl: libcurl: Unauthorized connection reuse due to a logical error
bugzilla·2026-07-03·CVSS 6.5
CVE-2026-8458 [MEDIUM] CVE-2026-8458 curl: libcurl: Unauthorized connection reuse due to a logical error
CVE-2026-8458 curl: libcurl: Unauthorized connection reuse due to a logical error
libcurl might in some circumstances reuse the wrong connection when asked to
do Negotiate-authenticated ones, even when they are set to use different
'services'.
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a request that was issued by an application could
wrongfully reuse an existing connection to the same server that was
authenticated using different services.
Bugzilla
CVE-2026-33983 FreeRDP: FreeRDP: Denial of Service via specially crafted Remote Desktop Protocol messages
bugzilla·2026-03-30·CVSS 6.5
CVE-2026-33983 [MEDIUM] CVE-2026-33983 FreeRDP: FreeRDP: Denial of Service via specially crafted Remote Desktop Protocol messages
CVE-2026-33983 FreeRDP: FreeRDP: Denial of Service via specially crafted Remote Desktop Protocol messages
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_upgrade() detects a mismatch via progressive_rfx_quant_cmp_equal() but only emits WLog_WARN, execution continues. The wrapped value (247) is used as a shift exponent, causing undefined behavior and an approximately 80 billion iteration loop (CPU DoS). This issue has been patched in version 3.24.2.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:8458 https://access.redhat.com/errata/RHSA-2026:8458
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:84
2026-07-03
Published