CVE-2026-8932
published 2026-07-03CVE-2026-8932: libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.40%
33.1th percentile
libcurl would reuse a previously created connection even when some mTLS config
related option had been changed that should have prohibited reuse.
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup. However, some TLS
settings related to client certificates were left out from the configuration
match checks, making them match too easily. In particular options related to
the private key.
Affected
197 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 7.10 – 7.10 | — |
| curl | curl | 7.10.1 – 7.10.1 | — |
| curl | curl | 7.10.2 – 7.10.2 | — |
| curl | curl | 7.10.3 – 7.10.3 | — |
| curl | curl | 7.10.4 – 7.10.4 | — |
| curl | curl | 7.10.5 – 7.10.5 | — |
| curl | curl | 7.10.6 – 7.10.6 | — |
| curl | curl | 7.10.7 – 7.10.7 | — |
| curl | curl | 7.10.8 – 7.10.8 | — |
| curl | curl | 7.11.0 – 7.11.0 | — |
| curl | curl | 7.11.1 – 7.11.1 | — |
| curl | curl | 7.11.2 – 7.11.2 | — |
| curl | curl | 7.12.0 – 7.12.0 | — |
| curl | curl | 7.12.1 – 7.12.1 | — |
| curl | curl | 7.12.2 – 7.12.2 | — |
| curl | curl | 7.12.3 – 7.12.3 | — |
| curl | curl | 7.13.0 – 7.13.0 | — |
| curl | curl | 7.13.1 – 7.13.1 | — |
| curl | curl | 7.13.2 – 7.13.2 | — |
| curl | curl | 7.14.0 – 7.14.0 | — |
| curl | curl | 7.14.1 – 7.14.1 | — |
| curl | curl | 7.15.0 – 7.15.0 | — |
| curl | curl | 7.15.1 – 7.15.1 | — |
| curl | curl | 7.15.2 – 7.15.2 | — |
| curl | curl | 7.15.3 – 7.15.3 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
curl vulnerability
vendor_ubuntu·2026-09-08
CVE-2026-8932 curl vulnerability
Title: curl vulnerability
Summary: curl could be made to expose sensitive information.
USN-8670-1 fixed a vulnerability in curl. This update provides the
corresponding update for Ubuntu 26.04 LTS.
Original advisory details:
Joshua Rogers discovered that curl incorrectly handled reusing
connections when client certificate settings changed. This could result
in the wrong client certificates being used, contrary to expectations.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
curl vulnerability
vendor_ubuntu·2026-08-25
CVE-2026-8932 curl vulnerability
Title: curl vulnerability
Summary: curl could be made to expose sensitive information.
USN-8670-1 fixed a vulnerability in curl. This update provides the
corresponding update for Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu
22.04 LTS.
Original advisory details:
Joshua Rogers discovered that curl incorrectly handled reusing
connections when client certificate settings changed. This could result
in the wrong client certificates being used, contrary to expectations.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
curl vulnerability
vendor_ubuntu·2026-08-24
CVE-2026-8932 curl vulnerability
Title: curl vulnerability
Summary: curl could be made to expose sensitive information.
Joshua Rogers discovered that curl incorrectly handled reusing connections
when client certificate settings changed. This could result in the wrong
client certificates being used, contrary to expectations.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse
vendor_redhat·2026-07-03·CVSS 7.5
CVE-2026-8932 [HIGH] CWE-1025 libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse
libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse
libcurl would reuse a previously created connection even when some mTLS config
related option had been changed that should have prohibited reuse.
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup. However, some TLS
settings related to client certificates were left out from the configuration
match checks, making them match too easily. In particular options related to
the private key.
A flaw was found in curl. The libcurl library, used for transferring data with URLs, could improperly reuse existing network connections. This occurred even when changes to mutual Transport Layer Security (mTLS) settings, particularly those for client
GHSA
libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.
ghsa_unreviewed·2026-07-03
CVE-2026-8932 libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.
libcurl would reuse a previously created connection even when some mTLS config
related option had been changed that should have prohibited reuse.
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup. However, some TLS
settings related to client certificates were left out from the configuration
match checks, making them match too easily. In particular options related to
the private key.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-8932 curl: libcurl: Security feature bypass due to improper mTLS connection reuse [fedora-all]
bugzilla·2026-07-31·CVSS 7.5
CVE-2026-8932 [HIGH] CVE-2026-8932 curl: libcurl: Security feature bypass due to improper mTLS connection reuse [fedora-all]
CVE-2026-8932 curl: libcurl: Security feature bypass due to improper mTLS connection reuse [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl would reuse a previously created connection even when some mTLS config
related option had been changed that should have prohibited reuse.
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup. However, some TLS
settings related to client certificates were left out from the configuration
match checks, making them match too easily. In particular options related to
the private key.
Bugzilla
CVE-2026-8932 davix: libcurl: Security feature bypass due to improper mTLS connection reuse [epel-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-8932 [HIGH] CVE-2026-8932 davix: libcurl: Security feature bypass due to improper mTLS connection reuse [epel-all]
CVE-2026-8932 davix: libcurl: Security feature bypass due to improper mTLS connection reuse [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl would reuse a previously created connection even when some mTLS config
related option had been changed that should have prohibited reuse.
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup. However, some TLS
settings related to client certificates were left out from the configuration
match checks, making them match too easily. In particular options related to
the private key.
Bugzilla
CVE-2026-8932 libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse
bugzilla·2026-07-03·CVSS 7.5
CVE-2026-8932 [HIGH] CVE-2026-8932 libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse
CVE-2026-8932 libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse
libcurl would reuse a previously created connection even when some mTLS config
related option had been changed that should have prohibited reuse.
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup. However, some TLS
settings related to client certificates were left out from the configuration
match checks, making them match too easily. In particular options related to
the private key.
Hackernews
ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
blogs_hackernews·2026-06-25
CVE-2026-8932 ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
It’s dumb out there again.
This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted apps doing sketchy crap, browser tricks jumping the fence, and “normal” workflows turning into phishing pipes because apparently email was not enough hell already.
The worst part is how cheap some of it feels. Not elite. Not cinematic. Just stale secrets, fake updates, lazy trust, and random boxes quietly becoming someone else’s infrastructure. Same internet, fresh headache. L
2026-07-03
Published