CVE Tools

25-Year-Old Vulnerability Patched in Curl

SecurityWeekBy Ionut Arghire

Patchcurllibcurl

Our summary

The open source data transfer tool and library curl has shipped a security update addressing 18 vulnerabilities (four medium and 14 low). The most notable issue is CVE-2026-8932, affecting libcurl applications (not the curl command-line tool) and related to mTLS connection reuse that can enable authentication bypass; it traces back to behavior introduced in version 7.7. Other tracked flaws include CVE-2026-8926 (credential confusion), CVE-2026-8925 (double-free), CVE-2026-9080 and CVE-2026-10536 (use-after-free), and CVE-2026-9547 (improper host validation). Because curl is widely used across servers and devices, unpatched flaws in libcurl can be attractive targets for attackers.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store