All CVEs
Vulnerability intelligence

CVE-2026-8932

curl curl

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.

CVSS Score
7.5
High
EPSS — Exploit Probability
0.4%
Riskier than 34% of all CVEs · checked 2026-09-19
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry

2 articles across 2 outlets · first covered Jun 25, 2026 · latest Jun 25, 2026

Coverage timeline