CVE-2026-8458
CVE-2026-8458 is a medium-severity vulnerability in Haxx Curl with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-488.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- EPSS exploit prediction: 0% (29th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-488
- Affected product: Haxx Curl
- Published:
- Last modified:
Description
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.
Frequently asked questions
- What is CVE-2026-8458?
- libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.
- How severe is CVE-2026-8458?
- CVE-2026-8458 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability none.
- Is CVE-2026-8458 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (29th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-8458?
- CVE-2026-8458 affects Haxx Curl. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-8458?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-8458 published?
- CVE-2026-8458 was published on 2026-07-03 and last updated on 2026-09-15.
References
- https://curl.se/docs/CVE-2026-8458.html
- https://curl.se/docs/CVE-2026-8458.json
- https://hackerone.com/reports/3721183
Affected products (1)
- cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
More vulnerabilities in Haxx Curl
- CVE-2026-19931 — Critical (CVSS 9.8): A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication,…
- CVE-2026-9079 — Critical (CVSS 9.8): libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the…
- CVE-2026-8925 — Critical (CVSS 9.8): The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing…
- CVE-2026-11856 — Critical (CVSS 9.8): Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then…
- CVE-2026-10536 — Critical (CVSS 9.8): A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via…
- CVE-2022-32221 — Critical (CVSS 9.8): When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data…
All CVEs affecting Haxx Curl →
Other CWE-488 vulnerabilities
- CVE-2026-16326 — Critical (CVSS 10.0): In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may…
- CVE-2026-16498 — Critical (CVSS 10.0): The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the…
- CVE-2026-19931 — Critical (CVSS 9.8): A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication,…
- CVE-2025-47928 — Critical (CVSS 9.1): Spotipy is a Python library for the Spotify Web API. As of commit 4f5759dbfb4506c7b6280572a4db1aabc1ac778d, using…
- CVE-2024-27455 — Critical (CVSS 9.1): In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token…
- CVE-2026-86492 — High (CVSS 8.5): In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation…