A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
https://hackerone.com/reports/3718195
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41503