Bug 2496764 (CVE-2026-8458) - CVE-2026-8458 curl: libcurl: Unauthorized connection reuse due to a logical error
Summary: CVE-2026-8458 curl: libcurl: Unauthorized connection reuse due to a logical e...
Keywords:
Status: NEW
Alias: CVE-2026-8458
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2511431 2511433 2511636 2511432
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-03 07:01 UTC by OSIDB Bzimport
Modified: 2026-10-07 13:35 UTC (History)
40 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2026:69707 0 None None None 2026-09-21 22:24:59 UTC
Red Hat Product Errata RHBA-2026:70194 0 None None None 2026-09-22 11:36:59 UTC
Red Hat Product Errata RHBA-2026:70266 0 None None None 2026-09-22 14:51:51 UTC
Red Hat Product Errata RHBA-2026:70696 0 None None None 2026-09-23 10:58:42 UTC
Red Hat Product Errata RHBA-2026:70831 0 None None None 2026-09-23 14:14:30 UTC
Red Hat Product Errata RHSA-2026:69125 0 None None None 2026-09-21 06:14:41 UTC
Red Hat Product Errata RHSA-2026:69126 0 None None None 2026-09-21 14:15:02 UTC
Red Hat Product Errata RHSA-2026:72506 0 None None None 2026-09-28 14:23:45 UTC

Description OSIDB Bzimport 2026-07-03 07:01:53 UTC
libcurl might in some circumstances reuse the wrong connection when asked to
do Negotiate-authenticated ones, even when they are set to use different
'services'.

libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.

When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a request that was issued by an application could
wrongfully reuse an existing connection to the same server that was
authenticated using different services.

Comment 6 Jon Orris 2026-09-21 06:14:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:69125 https://access.redhat.com/errata/RHSA-2026:69125

Comment 7 Jon Orris 2026-09-21 14:15:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:69126 https://access.redhat.com/errata/RHSA-2026:69126

Comment 8 Jon Orris 2026-09-28 14:23:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:72506 https://access.redhat.com/errata/RHSA-2026:72506


Note You need to log in before you can comment on or make changes to this bug.