CVE-2026-8286 affecting package curl for versions less than 8.11.1-10
Details
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.