CVE Tools
Back to feed
Patch released curl info-disclosure cryptography

В curl исправили уязвимость 25-летней давности

Хакер (xakep.ru)·By Мария Нефёдова··1 min read
CVE Tools coverage

The curl team released version 8.21.0, fixing 18 security vulnerabilities at once—an unusually large set for a single update. The most longstanding issue is CVE-2026-8932, which existed in the project for over 25 years and affected all versions up to 8.20.0 inclusive, related to improper handling of reused mTLS connections (client certificate/private key changes weren’t fully accounted for). This matters because embedded libcurl-based applications could inadvertently reuse a connection authenticated with prior credentials, while the curl command-line utility is not affected.