Curl · Curl · CVE-2026-8932
**Name of the Vulnerable Software and Affected Versions**
libcurl versions 7.7 through 8.20.x
**Description**
libcurl incorrectly reuses previously created connections from its connection pool even when mutual TLS (mTLS) configuration options have changed. The connection-reuse check fails to validate five specific client certificate settings: private key, key password, key type, cert type, and key blob. Consequently, two separate transfers that differ only by these settings may share the same connection and identity. This issue is estimated to affect over 30 billion devices worldwide, including operating systems, containers, CI/CD pipelines, package managers, SDKs, and automotive systems.
**Recommendations**
Update libcurl to version 8.21.0.