CVE-2026-8932
CVE-2026-8932
7.5
HighPublished:
Last updated:
Source:2499f714-1537-4658-8207-48ae4bb9eae9
Analyzed
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- High
- Availability
- None
Description
libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.
References
2499f714-1537-4658-8207-48ae4bb9eae9
https://curl.se/docs/CVE-2026-8932.html2499f714-1537-4658-8207-48ae4bb9eae9
https://curl.se/docs/CVE-2026-8932.json2499f714-1537-4658-8207-48ae4bb9eae9
https://hackerone.com/reports/3733910134c704f-9b21-4f2e-91b3-4a467353bcc0
https://hackerone.com/reports/3733910