Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-8458

Опубликовано: 03 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'.

libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.

When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
Версия от 7.46.0 (включая) до 8.20.0 (исключая)

EPSS

Процентиль: 24%
0.00315
Низкий

6.5 Medium

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.5
ubuntu
28 дней назад

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.

CVSS3: 6.5
msrc
27 дней назад

wrong reuse for different services

CVSS3: 6.5
debian
28 дней назад

libcurl might in some circumstances reuse the wrong connection when as ...

CVSS3: 6.5
github
28 дней назад

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.

suse-cvrf
23 дня назад

Security update for curl

EPSS

Процентиль: 24%
0.00315
Низкий

6.5 Medium

CVSS3

Дефекты

NVD-CWE-noinfo