HIGHVulnerability

CVE-2026-8932

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.

Properties

severity
HIGH
score
7.5
epss_score
0.00396
cve_id
CVE-2026-8932
signal_observed_at
2026-09-15T07:22:04+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
published_at
2026-07-03T07:16:25.363
last_modified
2026-09-15T07:16:33.407
epss_percentile
0.33266

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Authentication Bypass by Primary Weakness

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-8932 — Ninja Signal Threat Intelligence | Ninja Signal