Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8458

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.

A flaw was found in libcurl. A logical error in the connection pooling mechanism may cause libcurl to reuse an authenticated connection for an unintended service. This could allow an application to wrongfully reuse an existing connection to the same server that was authenticated for a different service, potentially leading to unauthorized access or information disclosure.

Отчет

This is an Important flaw in libcurl where a logical error in connection pooling can lead to unauthorized connection reuse. When an application uses Negotiate authentication with different service names on the same hostname and port, libcurl might incorrectly reuse an existing authenticated connection for an unintended service. This could result in information disclosure or unauthorized access to resources, bypassing intended service isolation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10curlAffected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected
Red Hat Enterprise Linux 8curlAffected
Red Hat Enterprise Linux 9curlAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected
Red Hat OpenShift Dev Spacesdevspaces/code-rhel9Affected
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Not affected
Red Hat JBoss Core Services 2.4.62.SP5FixedRHSA-2026:5686919.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-305
https://bugzilla.redhat.com/show_bug.cgi?id=2496764curl: libcurl: Unauthorized connection reuse due to a logical error

EPSS

Процентиль: 44%
0.00543
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.

CVSS3: 6.5
nvd
3 месяца назад

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.

CVSS3: 6.5
msrc
около 1 месяца назад

wrong reuse for different services

CVSS3: 6.5
debian
3 месяца назад

libcurl might in some circumstances reuse the wrong connection when as ...

CVSS3: 6.5
github
3 месяца назад

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.

EPSS

Процентиль: 44%
0.00543
Низкий

8.1 High

CVSS3