USN-8487-2: curl regression
Ubuntu patches an incomplete curl fix for CVE-2026-8927 and related connection-reuse flaws.
Ubuntu USN-8487-2 corrects an incomplete fix for CVE-2026-8927 that was shipped in USN-8487-1. The original issues include CVE-2026-8286, where curl can reuse a live connection during STARTTLS upgrades even when the TLS configuration does not match, potentially forcing an unintended TLS setup. A second flaw incorrectly reuses connections for Negotiate-authenticated requests across different services, which a remote attacker could possibly use to reach resources authenticated for another service.
- USN-8487-1 incompletely fixed CVE-2026-8927 in curl.
- CVE-2026-8286 can reuse STARTTLS connections despite mismatched TLS settings.
- A separate flaw reuses Negotiate-authenticated connections across different services.
- No in-the-wild exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-89279.1<1%When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication…published · haxx curl PoC +1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-8927 |
USN-8487-1 fixed vulnerabilities in curl. Unfortunately that update contained an incomplete fix for CVE-2026-8927. This update fixes the problem. Original advisory details: Andrew Nesbitt discovered that curl could reuse an existing live connection during STARTTLS-based connection upgrades even when the TLS configuration did not match. A remote attacker could possibly use this issue to cause curl to use an unintended TLS configuration. (CVE-2026-8286) Muhamad Arga Reksapati discovered that curl incorrectly reused connections for Negotiate-authenticated requests when different services were involved. A remote attacker could possibly use this issue to access resources authenticated for…
This source does not provide full text. Read it at ubuntu.com.