{"id":"AZL-91809","summary":"CVE-2026-8458 affecting package curl for versions less than 8.11.1-10","details":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n'services'.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.","modified":"2026-09-09T05:29:25Z","published":"2026-07-03T07:16:24Z","upstream":["CVE-2026-8458"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458"}],"affected":[{"package":{"name":"curl","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/curl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.11.1-10"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91809.json"}}],"schema_version":"1.9.0"}