CVE-2026-8932
incomplete mTLS config matching in conn reuse
Description
libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.
No summary for this CVE yet.
CVSS Vector Breakdown
Exploitability
AV:NAttack VectorNetwork
AC:LAttack ComplexityLow
PR:NPrivileges RequiredNone
UI:NUser InteractionNone
Scope
S:UScopeUnchanged
Impact
C:NConfidentialityNone
I:HIntegrityHigh
A:NAvailabilityNone
Weaknesses
Affected Products
haxx
oss-project·SEaka haxx.se
curl
oss-project·USaka wcurl, libcurl
Exploitability
Official Patch Available
References
News mentions
4- В curl исправили уязвимость 25-летней давностиru-ru·Хакер (xakep.ru)· Patch curl info-disclosure
- Curl v8.21.0 Release Fixes 18 Security Flawsen-us·Daily CyberSecurity (securityonline.info)· Patch curl web-app
- ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Storiesen·The Hacker News· Research LG webOS ics-ot-iot
- 25-Year-Old Vulnerability Patched in Curlen-us·SecurityWeek· Patch curl web-app
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-8932 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows
