https://seclists.org/oss-sec/2026/q2/1012: [SECURITY ADVISORIES] for curl 8.21.0
Published Jun 24, 2026
·Updated
Affected Software
1 affected component
curl curl<8.21.0
Frequently Asked Questions
1
What is the severity of CVE-2026-8286?
CVE-2026-8286 is classified as a low severity vulnerability.
2
What issue does CVE-2026-8458 address?
CVE-2026-8458 addresses the wrong reuse of connections for different services.
3
How do I fix CVE-2026-8924?
To fix CVE-2026-8924, ensure that domain names do not end with a trailing dot when handling super cookies.
4
Is there a workaround for CVE-2026-8286?
A workaround for CVE-2026-8286 involves properly managing STARTTLS connection reusability.
5
Which version of curl is affected by CVE-2026-8458?
CVE-2026-8458 affects curl version 8.21.0 and potentially earlier versions.