CVE-2026-8932

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP5 security update

Beschreibung

libcurl würde eine zuvor erstellte Verbindung wiederverwenden, auch wenn sich eine mTLS-Konfigurationsoption geändert hatte, die eigentlich die Wiederverwendung hätte verbieten sollen. libcurl behält zuvor verwendete Verbindungen in einem Verbindungspool für nachfolgende Übertragungen zur Wiederverwendung bei, sofern eine davon zum Setup passt. Allerdings wurden einige TLS-Einstellungen im Zusammenhang mit Client-Zertifikaten von den Konfigurationsabgleichschecks ausgelassen, wodurch sie zu leicht übereinstimmten. Insbesondere Optionen in Bezug auf das private Schlüssel.

Metriken

Severity
high
PoC (öffentlich gemeldet)
7.5
Quelle: nvd-v3
33.1 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-19 13:28 UTC

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-07-07 23:18 UTC· nvd@nist.gov
    • CWE: NVD-CWE-Other
    • CPE Configuration: OR *cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* versions from (including) 7.7 up to (excluding) 8.21.0
    • Reference Type: curl: https://curl.se/docs/CVE-2026-8932.html Types: Patch, Vendor Advisory
    • Reference Type: curl: https://curl.se/docs/CVE-2026-8932.json Types: Vendor Advisory
  2. New CVE Received2026-07-03 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
    • Affected: curl
    • Description: libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.
    • Reference: https://curl.se/docs/CVE-2026-8932.html
    • Reference: https://curl.se/docs/CVE-2026-8932.json

Betroffene Betriebssysteme

  • linux

    ubuntu / curlbionic

  • linux

    ubuntu / curlfocal

  • linux

    ubuntu / curlnoble

  • linux

    ubuntu / curlquesting

  • linux

    ubuntu / curlresolute

  • linux

    ubuntu / curltrusty

  • linux

    ubuntu / curlxenial

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    http_server2.4.0 – 2.4.68

  • Apple

    iOS18.7.10

  • Apple

    iOS26.6.1

  • Apple

    iPadOS18.7.10

  • Apple

    iPadOS26.6.1

  • Apple

    macOSTahoe 26.6.2

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.55

  • bitnami

    apache

  • haxx

    curl7.30.0 – 8.21.0

  • haxx

    curl7.46.0 – 8.20.0

  • haxx

    curl7.46.0 – 8.21.0

  • haxx

    curl7.69.0 – 8.21.0

  • haxx

    curl8.11.0 – 8.21.0

  • Hitachi Energy

    RTU500< 13.9.1

    gefixt in 13.9.1

  • Splunk

    Splunk Enterprise< 10.0.9

    gefixt in 10.0.9

  • Splunk

    Splunk Enterprise< 10.2.6

    gefixt in 10.2.6

  • Splunk

    Splunk Enterprise< 10.4.2

    gefixt in 10.4.2

  • Splunk

    Splunk Enterprise< 9.4.14

    gefixt in 9.4.14

Quellen & Referenzen

Verknüpfte CVEs

5 weitere CVEs anzeigen
IDCVE-2026-8932