Patch released curl info-disclosure cryptography
В curl исправили уязвимость 25-летней давности
CVE Tools coverage
The curl team released version 8.21.0, fixing 18 security vulnerabilities at once—an unusually large set for a single update. The most longstanding issue is CVE-2026-8932, which existed in the project for over 25 years and affected all versions up to 8.20.0 inclusive, related to improper handling of reused mTLS connections (client certificate/private key changes weren’t fully accounted for). This matters because embedded libcurl-based applications could inadvertently reuse a connection authenticated with prior credentials, while the curl command-line utility is not affected.