PT-2026-51751 · Curl+4 · Curl+4

·

CVE-2026-8932

·

Published

2026-06-24

·

Updated

2026-09-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions libcurl versions 7.7 through 8.20.x
Description libcurl incorrectly reuses previously created connections from its connection pool even when mutual TLS (mTLS) configuration options have changed. The connection-reuse check fails to validate five specific client certificate settings: private key, key password, key type, cert type, and key blob. Consequently, two separate transfers that differ only by these settings may share the same connection and identity. This issue is estimated to affect over 30 billion devices worldwide, including operating systems, containers, CI/CD pipelines, package managers, SDKs, and automotive systems.
Recommendations Update libcurl to version 8.21.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91797
AZL-91827
CVE-2026-8932
ECHO-B5E8-7A05-5B42
JLSEC-2026-1217
OPENSUSE-SU-2026:11230-1
RHSA-2026:34975
USN-8670-1
USN-8670-2
USN-8670-3

Affected Products

Ibm Aix
Linuxmint
Ubuntu
Curl
Libcurl