Medium severity6.5NVD Advisory· Published Jul 3, 2026· Updated Sep 15, 2026
CVE-2026-8458
CVE-2026-8458
Description
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services".
libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19- osv-coords17 versionspkg:apk/chainguard/eco-python-curlpkg:apk/chainguard/eco-python-curl-minimalpkg:apk/chainguard/eco-python-curl-minimal-binpkg:apk/chainguard/eco-python-curl-minimal-devpkg:apk/chainguard/eco-python-curl-minimal-docpkg:apk/chainguard/eco-python-curl-minimal-staticpkg:apk/chainguard/eco-python-curl-nghttp2pkg:apk/chainguard/eco-python-curl-nghttp2-binpkg:apk/chainguard/eco-python-curl-nghttp2-devpkg:apk/chainguard/eco-python-curl-nghttp2-staticpkg:rpm/almalinux/curlpkg:rpm/almalinux/curl-minimalpkg:rpm/almalinux/libcurlpkg:rpm/almalinux/libcurl-develpkg:rpm/almalinux/libcurl-minimalpkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweed
< 8.21.0-r0+ 16 more
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.12.1-4.el10_2.6
- (no CPE)range: < 7.76.1-40.el9_8.7
- (no CPE)range: < 8.12.1-4.el10_2.6
- (no CPE)range: < 8.12.1-4.el10_2.6
- (no CPE)range: < 8.12.1-4.el10_2.6
- (no CPE)range: < 8.14.1-160000.8.1
- (no CPE)range: < 8.21.0-1.1
Patches
Vulnerability mechanics
References
3- curl.se/docs/CVE-2026-8458.htmlnvdPatchVendor Advisory
- hackerone.com/reports/3721183nvdExploitIssue TrackingThird Party Advisory
- curl.se/docs/CVE-2026-8458.jsonnvdVendor Advisory
News mentions
1- 25-Year-Old Vulnerability in cURL Used by 30 Billion Devices Finally PatchedCyber Security News · Jun 25, 2026