Back

HIGH

incomplete mTLS config matching in conn reuse

Published Jul 3, 2026

Description

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.

Affected products

Remediation

Red Hat statement

This is an Important security feature bypass in libcurl where mTLS connection reuse may occur despite changes to client certificate settings. This could lead to applications using libcurl with mTLS to inadvertently use a less secure connection than intended, potentially compromising data confidentiality or integrity. This issue primarily affects applications that dynamically alter mTLS client certificate configurations and reuse connections.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (2)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner curl
Published Jul 3, 2026
Updated Sep 15, 2026
Reserved May 19, 2026
CISA Vulnrichment
Updated Jul 6, 2026
NVD
Status Modified
Modified Sep 15, 2026
Red Hat
Severity Moderate
Public date Jul 3, 2026