CVE-2026-8286
Low
wrong STARTTLS connection reuse
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
Exploit probability
0.5%
Published
June 24, 2026
Required by
Not available
Last source change
June 24, 2026
02 / AFFECTED SOFTWARE
Affected packages
124 explicit affected versions
237 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2026-8286
View original source
Open Source Vulnerabilities
CURL-CVE-2026-8286
View original source
05 / REFERENCES