Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8286

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established.

Отчет

This is an Important flaw as curl may establish an insecure connection when attempting to upgrade a transfer with STARTTLS, potentially reusing an existing connection with mismatched TLS configurations. This could lead to unexpected data exposure or compromise, particularly in environments where curl is used for sensitive data transfers and relies on STARTTLS for security.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6curlAffected
Red Hat Enterprise Linux 7curlAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Not affected
Red Hat Enterprise Linux 10curlFixedRHSA-2026:5545017.08.2026
Red Hat Enterprise Linux 8curlFixedRHSA-2026:5746220.08.2026
Red Hat Enterprise Linux 9curlFixedRHSA-2026:5543917.08.2026
Red Hat Enterprise Linux 9curlFixedRHSA-2026:5543917.08.2026
Red Hat JBoss Core Services 2.4.62.SP5FixedRHSA-2026:5686919.08.2026
Red Hat OpenShift Container Platform 4.22rhcos-4.22.9.8.202608251819FixedRHSA-2026:6044001.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2496763curl: curl: Insecure connection establishment due to TLS configuration mismatch

EPSS

Процентиль: 24%
0.00309
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
2 месяца назад

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

CVSS3: 8.1
nvd
2 месяца назад

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

CVSS3: 8.1
msrc
2 месяца назад

wrong STARTTLS connection reuse

CVSS3: 8.1
debian
2 месяца назад

A vulnerability exists where a new transfer that uses STARTTLS to upgr ...

rocky
25 дней назад

Important: curl security, bug fix, and enhancement update

EPSS

Процентиль: 24%
0.00309
Низкий

8.1 High

CVSS3

Уязвимость CVE-2026-8286