PT-2026-51751 · Curl+4 · Curl+4
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
libcurl versions 7.7 through 8.20.x
Description
libcurl incorrectly reuses previously created connections from its connection pool even when mutual TLS (mTLS) configuration options have changed. The connection-reuse check fails to validate five specific client certificate settings: private key, key password, key type, cert type, and key blob. Consequently, two separate transfers that differ only by these settings may share the same connection and identity. This issue is estimated to affect over 30 billion devices worldwide, including operating systems, containers, CI/CD pipelines, package managers, SDKs, and automotive systems.
Recommendations
Update libcurl to version 8.21.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Aix
Linuxmint
Ubuntu
Curl
Libcurl