CVE-2026-8458
Low
wrong reuse for different services
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.
Exploit probability
0.5%
Published
June 24, 2026
Required by
Not available
Last source change
June 24, 2026
02 / AFFECTED SOFTWARE
Affected packages
103 explicit affected versions
207 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2026-8458
View original source
Open Source Vulnerabilities
CURL-CVE-2026-8458
View original source
05 / REFERENCES