Skip to main content
Version: v1.2.x

CVE-2026-8932

CVE Details

Visit the official vulnerability details page for CVE-2026-8932 to learn more.

Initial Publication

07/03/2026

Last Update

07/07/2026

Third Party Dependency

curl-minimal

NIST CVE Summary

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.

CVE Severity

7.5

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Analyzed

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.2.1⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.