Authentication Bypass by Primary Weakness in cURL - CVE-2026-8932
Published: June 24, 2026
cURL
Detailed vulnerability description
The vulnerability allows a remote user to bypass client certificate authentication.
The vulnerability exists due to authentication bypass by primary weakness in libcurl connection reuse logic when reusing a previously established connection after changing mTLS client certificate settings. A remote user can reuse a connection with mismatched client certificate configuration to bypass client certificate authentication.
The issue affects libcurl and does not affect the curl command line tool.