Authentication Bypass by Primary Weakness in cURL - CVE-2026-8932
Published: June 24, 2026
Vulnerability details
The vulnerability allows a remote user to bypass client certificate authentication.
The vulnerability exists due to authentication bypass by primary weakness in libcurl connection reuse logic when reusing a previously established connection after changing mTLS client certificate settings. A remote user can reuse a connection with mismatched client certificate configuration to bypass client certificate authentication.
The issue affects libcurl and does not affect the curl command line tool.
Affected software
LANTIME Operating System Firmware (LTOS)
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
openEuler
Anolis OS
curl (Ubuntu package)
curl-help
libcurl-devel
libcurl
curl-debugsource
curl-debuginfo
curl
curl-doc
libcurl-minimal
curl-minimal
curl (Red Hat package)
How to mitigate CVE-2026-8932
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
curl (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.24+esm12, 7.68.0-1ubuntu2.25+esm7, 7.81.0-1ubuntu1.27, 8.5.0-2ubuntu10.13, 8.18.0-1ubuntu2.5
curl-help - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
libcurl-devel - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
libcurl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-debugsource - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-debuginfo - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-doc - update to 8.4.0-25
libcurl-minimal - update to 8.4.0-25
libcurl-devel - update to 8.4.0-25
libcurl - update to 8.4.0-25
curl-minimal - update to 8.4.0-25
curl - update to 8.4.0-25
curl (Red Hat package) - update to 8.12.1-1.el10_0.10
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Ubuntu update for curl
- Ubuntu update for curl
- openEuler 24.03 LTS SP3 update for curl
- openEuler 24.03 LTS SP1 update for curl
- openEuler 22.03 LTS SP4 update for curl
- openEuler 20.03 LTS SP4 update for curl
- openEuler 24.03 LTS SP4 update for curl
- Anolis OS update for curl
- Red Hat Enterprise Linux 10 update for curl
- Ubuntu update for curl