CVE Explorer
CVE-2026-8932
libcurl would reuse a previously created connection even when some mTLS config
related option had been changed that should have prohibited reuse.
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup. However, some TLS
settings related to client certificates were left out from the configuration
match checks, making them match too easily. In particular options related to
the private key.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"curl","vendor":"curl","versions":[{"lessThanOrEqual":"8.20.0","status":"affected","version":"8.20.0","versionType":"semver"},{"lessThanOrEqual":"8.19.0","status":"affected","version":"8.19.0","versionType":"semver"},{"lessThanOrEqual":"8.18.0","status":"affected","version":"8.18.0","versionType":"semver"},{"lessThanOrEqual":"8.17.0","status":"affected","version":"8.17.0","versionType":"semver"},{"lessThanOrEqual":"8.16.0","status":"affected","version":"8.16.0","versionType":"semver"},{"lessThanOrEqual":"8.15.0","status":"affected","version":"8.15.0","ve…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5d9c82d455a9f431afe61f3a25cabf47a47a746fd61f43456ef33b7eeabf9c75 · sha256:fe0062df4ae22546… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5d9c82d455a9f431afe61f3a25cabf47a47a746fd61f43456ef33b7eeabf9c75 · sha256:fe0062df4ae22546… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"description":"CWE-305 Authentication Bypass by Primary Weakness","lang":"en"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5d9c82d455a9f431afe61f3a25cabf47a47a746fd61f43456ef33b7eeabf9c75 · sha256:fe0062df4ae22546… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"www","url":"https://curl.se/docs/CVE-2026-8932.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5d9c82d455a9f431afe61f3a25cabf47a47a746fd61f43456ef33b7eeabf9c75 · sha256:fe0062df4ae22546… · /containers/cna/references/1
{"name":"json","url":"https://curl.se/docs/CVE-2026-8932.json"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5d9c82d455a9f431afe61f3a25cabf47a47a746fd61f43456ef33b7eeabf9c75 · sha256:fe0062df4ae22546… · /containers/cna/references/0
{"name":"issue","url":"https://hackerone.com/reports/3733910"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5d9c82d455a9f431afe61f3a25cabf47a47a746fd61f43456ef33b7eeabf9c75 · sha256:fe0062df4ae22546… · /containers/cna/references/2
{"tags":["exploit"],"url":"https://hackerone.com/reports/3733910"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5d9c82d455a9f431afe61f3a25cabf47a47a746fd61f43456ef33b7eeabf9c75 · sha256:fe0062df4ae22546… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.