libcurl mTLS flaw allowed wrong client certificate on reused connections

A security vulnerability tracked as CVE-2026-8932 has been discovered in libcurl, affecting versions 7.7 through 8.20.0. The flaw stems from an incomplete comparison in libcurl's connection-reuse logic, where five private-key-related fields were excluded from the check that decides whether a pooled TLS connection can be reused. As a result, two handles sharing the same certificate file but using different private keys or passwords could incorrectly reuse the same authenticated connection. A parallel issue in the TLS session cache also allowed sessions tied to different client certificates to collide. The vulnerability was reported by Joshua Rogers of Aisle Research and has been fixed in libcurl 8.21.0, released on June 24, 2026.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in