CVE-2026-8932
Publication date 24 June 2026
Last updated 25 August 2026
Ubuntu priority
Cvss 3 Severity Score
Description
libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.
Why is this CVE low priority?
Upstream defined this as low severity
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| curl | 26.04 LTS resolute | Ignored changes too intrusive |
| 24.04 LTS noble |
Fixed 8.5.0-2ubuntu10.13
|
|
| 22.04 LTS jammy |
Fixed 7.81.0-1ubuntu1.27
|
|
| 20.04 LTS focal |
Fixed 7.68.0-1ubuntu2.25+esm7
|
|
| 18.04 LTS bionic |
Fixed 7.58.0-2ubuntu3.24+esm12
|
|
| 16.04 LTS xenial | Ignored changes too intrusive | |
| 14.04 LTS trusty | Ignored changes too intrusive |
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialSeverity score breakdown
CVSS version: CVSS v3.0
Base score
7.5 · High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
References
Related Ubuntu Security Notices (USN)
- USN-8670-1
- curl vulnerability
- 24 August 2026
- USN-8670-2
- curl vulnerability
- 25 August 2026