CVE-2026-8286: wrong STARTTLS connection reuse
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 8.21.0-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.11.1-10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8286?
CVE-2026-8286 has a risk rating of 28, indicating a medium severity vulnerability.
How do I fix CVE-2026-8286?
To fix CVE-2026-8286, ensure you update to the latest version of the affected software, Debian/curl.
What systems are affected by CVE-2026-8286?
CVE-2026-8286 specifically affects users of Debian/curl that implement STARTTLS for connection upgrades.
What type of vulnerability is CVE-2026-8286?
CVE-2026-8286 is a connection reuse vulnerability related to improper TLS configuration handling.
When was CVE-2026-8286 published?
CVE-2026-8286 was published on July 3, 2026.