ZeroHour

CVE-2026-8286

PoC
CVSS 3.1
8.1 high
EPSS
<1%p24
Published
()
Modified
Description

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

Vendors
haxx
Products
curl
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.