Bug 2496763 (CVE-2026-8286)

Summary: CVE-2026-8286 curl: curl: Insecure connection establishment due to TLS configuration mismatch
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, dbosanac, dpaolell, jdelft, jreimann, jupierce, kevinxue, lgarciaa, mbiarnes, mdessi, mrizzi, pcattana, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sdawley, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2497494, 2497495, 2497496    
Bug Blocks:    

Description OSIDB Bzimport 2026-07-03 07:01:49 UTC
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.

Comment 2 errata-xmlrpc 2026-08-17 04:40:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:55450 https://access.redhat.com/errata/RHSA-2026:55450

Comment 3 errata-xmlrpc 2026-08-17 05:43:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55439 https://access.redhat.com/errata/RHSA-2026:55439

Comment 4 errata-xmlrpc 2026-08-20 11:34:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:57462 https://access.redhat.com/errata/RHSA-2026:57462

Comment 5 errata-xmlrpc 2026-09-01 21:38:40 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.22

Via RHSA-2026:60440 https://access.redhat.com/errata/RHSA-2026:60440

Comment 6 Jon Orris 2026-09-15 09:19:20 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.22

Via RHSA-2026:66357 https://access.redhat.com/errata/RHSA-2026:66357