A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
{
"package": "curl",
"URL": "https://curl.se/docs/CVE-2026-8286.json",
"last_affected": "8.20.0",
"issue": "https://hackerone.com/reports/3718195",
"affects": "both",
"severity": "Low",
"www": "https://curl.se/docs/CVE-2026-8286.html",
"CWE": {
"desc": "Improper Certificate Validation",
"id": "CWE-295"
}
}"https://curl.se/docs/CURL-CVE-2026-8286.json"
"2026-06-24T08:04:22Z"
[
{
"target": {
"file": "lib/url.c",
"function": "url_attach_existing"
},
"id": "CURL-CVE-2026-8286-36e2c702",
"source": "https://github.com/curl/curl.git/commit/a86efdd7ca5433de9231e650f18247de8319ad16",
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1266.0,
"function_hash": "255927142008379728411564186004947874680"
},
"signature_version": "v1"
},
{
"target": {
"file": "lib/url.c"
},
"id": "CURL-CVE-2026-8286-77b46469",
"source": "https://github.com/curl/curl.git/commit/a86efdd7ca5433de9231e650f18247de8319ad16",
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"79579754339828812704100697271177389006",
"201266269548055692107771773077340523131",
"44554694905850861517360692375013809510",
"189414445810292435800822926511135861207",
"82119597603467486091946665569863295589",
"32205138923765805259532529366519825293",
"1595719663087089186438367489630032937",
"13432913159457392423885733736079711573",
"271450291167908716433797841144313127094",
"309805148214852052097449817889325145308",
"174179530067375282946781672509532631351",
"265309687202118156829353374555176487481",
"253951827240995577087558813189304453562",
"22402060057554271931103934273904839270",
"189927906393150869117975492566210925676",
"150612367893260474494433923894551181895"
]
},
"signature_version": "v1"
},
{
"target": {
"file": "lib/url.c",
"function": "url_match_ssl_use"
},
"id": "CURL-CVE-2026-8286-916399bb",
"source": "https://github.com/curl/curl.git/commit/a86efdd7ca5433de9231e650f18247de8319ad16",
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 443.0,
"function_hash": "239676500179737488359518133324904996049"
},
"signature_version": "v1"
},
{
"target": {
"file": "lib/url.c",
"function": "url_match_ssl_config"
},
"id": "CURL-CVE-2026-8286-f34f0cee",
"source": "https://github.com/curl/curl.git/commit/a86efdd7ca5433de9231e650f18247de8319ad16",
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 358.0,
"function_hash": "245058740434124744257493381128513890250"
},
"signature_version": "v1"
}
]