All findings

CVE-2026-8286 low

Mythos finds curl STARTTLS connection-reuse flaw

curl credits Andrew Nesbitt, powered by Mythos, for a connection-reuse error that could keep using a plaintext connection when STARTTLS was requested.

Bug class
Incorrect STARTTLS connection reuse
Affected codebase
curl and libcurl
Credited system
Claude Mythos Preview
Disclosed
June 24, 2026
Attribution
Direct source attribution
Severity
low
Source status: curl's advisory names Andrew Nesbitt, powered by Mythos, as finder and rates the issue Low. Daniel Stenberg's primary write-up describes the report and validation process.

Summary

CVE-2026-8286 concerns curl’s connection cache. Under a specific sequence of transfers, a request that required a STARTTLS-upgraded connection could reuse an existing connection with the wrong security state.

curl rates the issue Low. That upstream rating is retained despite the finding being useful evidence of model-assisted reasoning about cross-request state.

Attribution

The finder credit directly names Mythos, making this a direct upstream attribution rather than a claim inferred from the researcher’s tooling.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.