Back

HIGH

wrong STARTTLS connection reuse

Published Jul 3, 2026

Description

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

Affected products

Remediation

Red Hat statement

This is an Important flaw as `curl` may establish an insecure connection when attempting to upgrade a transfer with STARTTLS, potentially reusing an existing connection with mismatched TLS configurations. This could lead to unexpected data exposure or compromise, particularly in environments where `curl` is used for sensitive data transfers and relies on STARTTLS for security.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner curl
Published Jul 3, 2026
Updated Sep 15, 2026
Reserved May 11, 2026
CISA Vulnrichment
Updated Jul 6, 2026
NVD
Status Modified
Modified Sep 15, 2026
Red Hat
Severity Important
Public date Jul 3, 2026
ENISA EUVD
Assigner curl
Published Jul 3, 2026
Updated Sep 15, 2026
Exploited since n/a
EUVD-2026-41503