Summary
CVE-2026-8286 concerns curl’s connection cache. Under a specific sequence of transfers, a request that required a STARTTLS-upgraded connection could reuse an existing connection with the wrong security state.
curl rates the issue Low. That upstream rating is retained despite the finding being useful evidence of model-assisted reasoning about cross-request state.
Attribution
The finder credit directly names Mythos, making this a direct upstream attribution rather than a claim inferred from the researcher’s tooling.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.