Authentication Bypass by Primary Weakness in cURL - CVE-2026-8932

 

Authentication Bypass by Primary Weakness in cURL - CVE-2026-8932

Published: June 24, 2026


Vulnerability identifier: #VU135079
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-8932
CWE-ID: CWE-305
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass client certificate authentication.

The vulnerability exists due to authentication bypass by primary weakness in libcurl connection reuse logic when reusing a previously established connection after changing mTLS client certificate settings. A remote user can reuse a connection with mismatched client certificate configuration to bypass client certificate authentication.

The issue affects libcurl and does not affect the curl command line tool.


Affected software

cURL
LANTIME Operating System Firmware (LTOS)
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
openEuler
Anolis OS
curl (Ubuntu package)
curl-help
libcurl-devel
libcurl
curl-debugsource
curl-debuginfo
curl
curl-doc
libcurl-minimal
curl-minimal
curl (Red Hat package)

How to mitigate CVE-2026-8932

Install security update from vendor's website.

cURL - update to 8.21.0
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
curl (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.24+esm12, 7.68.0-1ubuntu2.25+esm7, 7.81.0-1ubuntu1.27, 8.5.0-2ubuntu10.13, 8.18.0-1ubuntu2.5
curl-help - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
libcurl-devel - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
libcurl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-debugsource - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-debuginfo - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-doc - update to 8.4.0-25
libcurl-minimal - update to 8.4.0-25
libcurl-devel - update to 8.4.0-25
libcurl - update to 8.4.0-25
curl-minimal - update to 8.4.0-25
curl - update to 8.4.0-25
curl (Red Hat package) - update to 8.12.1-1.el10_0.10

External References

Related Security Bulletins