Bug 2496763 (CVE-2026-8286) - CVE-2026-8286 curl: curl: Insecure connection establishment due to TLS configuration mismatch
Summary: CVE-2026-8286 curl: curl: Insecure connection establishment due to TLS config...
Keywords:
Status: NEW
Alias: CVE-2026-8286
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2497494 2497495 2497496
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-03 07:01 UTC by OSIDB Bzimport
Modified: 2026-08-24 13:37 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2026:57594 0 None None None 2026-08-20 16:10:22 UTC
Red Hat Product Errata RHBA-2026:59025 0 None None None 2026-08-24 13:37:32 UTC
Red Hat Product Errata RHSA-2026:55439 0 None None None 2026-08-17 05:43:56 UTC
Red Hat Product Errata RHSA-2026:55450 0 None None None 2026-08-17 04:40:23 UTC
Red Hat Product Errata RHSA-2026:57462 0 None None None 2026-08-20 11:34:16 UTC

Description OSIDB Bzimport 2026-07-03 07:01:49 UTC
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.

Comment 2 errata-xmlrpc 2026-08-17 04:40:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:55450 https://access.redhat.com/errata/RHSA-2026:55450

Comment 3 errata-xmlrpc 2026-08-17 05:43:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55439 https://access.redhat.com/errata/RHSA-2026:55439

Comment 4 errata-xmlrpc 2026-08-20 11:34:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:57462 https://access.redhat.com/errata/RHSA-2026:57462


Note You need to log in before you can comment on or make changes to this bug.