Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8286

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established.

Отчет

This is an Important flaw as curl may establish an insecure connection when attempting to upgrade a transfer with STARTTLS, potentially reusing an existing connection with mismatched TLS configurations. This could lead to unexpected data exposure or compromise, particularly in environments where curl is used for sensitive data transfers and relies on STARTTLS for security.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10curlAffected
Red Hat Enterprise Linux 6curlAffected
Red Hat Enterprise Linux 7curlAffected
Red Hat Enterprise Linux 8curlAffected
Red Hat Enterprise Linux 9curlAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat OpenShift Dev Spacesdevspaces/code-rhel9Affected
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Not affected
Red Hat Hardened Imagescurl-main-8.21.0-0.1.hum1FixedRHSA-2026:2901724.06.2026
Red Hat Hardened Imagesrust-main-1.96.1-1.hum1FixedRHSA-2026:3497502.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2496763curl: curl: Insecure connection establishment due to TLS configuration mismatch

EPSS

Процентиль: 23%
0.00309
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
28 дней назад

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

CVSS3: 8.1
nvd
28 дней назад

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

CVSS3: 8.1
msrc
19 дней назад

wrong STARTTLS connection reuse

CVSS3: 8.1
debian
28 дней назад

A vulnerability exists where a new transfer that uses STARTTLS to upgr ...

CVSS3: 8.1
github
28 дней назад

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

EPSS

Процентиль: 23%
0.00309
Низкий

8.1 High

CVSS3