Redpacketsecurity libcurl TLS Session Resumption Issues Disclosed
Article Content
- •libcurl's TLS session resumption can expose user identities.
- •Mutual TLS connections may lead to identity mix-ups due to ENGINE misconfigurations.
- •Both issues were classified as informative, with no CVEs assigned.
Two security issues related to libcurl's handling of TLS sessions were disclosed. The first issue allows a TLS session to be reused without a client certificate, potentially exposing user identities. The second issue involves mutual TLS (mTLS) connections where different OpenSSL ENGINEs could lead to identity mix-ups when reusing connections. Both vulnerabilities were reported to HackerOne and classified as informative rather than critical vulnerabilities. The curl security team emphasized that the issues stemmed from documentation gaps rather than exploitable flaws. No CVEs were assigned, and the reports were closed without a bounty. Users of libcurl are advised to review the updated documentation to avoid potential misuse of the CURLOPT_SSL_CTX_FUNCTION option.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…