Curl patches 18 vulnerabilities, including 25-year-old libcurl authentication-bypass flaw CVE-2026-8932

Curl released an update fixing 18 security vulnerabilities, including a 25-year-old flaw in libcurl that could let applications reuse the wrong mutual-TLS identity and bypass authentication. The bugs affect curl/libcurl, with four rated medium and 14 low severity; the oldest, CVE-2026-8932, was introduced in curl 7.7 in 2001 and affects libcurl applications rather than the curl command-line tool. Other fixed issues include CVE-2026-8926, CVE-2026-8925, CVE-2026-9080, CVE-2026-10536, and CVE-2026-9547.
Why it matters: Curl and libcurl are embedded across servers, apps, phones, cars, and enterprise software, so even medium-severity flaws can have broad downstream impact. Organizations and software vendors that ship or depend on libcurl should update promptly and review where client-certificate authentication is used.

Sources

25-Year-Old Vulnerability Patched in Curl
Ionut Arghire 2026.06.25 100% relevant
This article establishes a new tracked story around curl's June 2026 security release and the specific long-lived libcurl flaw CVE-2026-8932, which is not represented in the existing story list.
← Back to all stories