CVE-2026-11564

Summary

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup.

An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.

Affected Software

VendorProductVersion RangeStatus
curlcurl8.17.0 < 8.20.1affected
curlcurleefd03c572996e5de4dec4fe295ad6f103e0eefc < d69bfad3fa3daf5e72331f6870667607828d5891affected
curlcurl8.20.0affected
curlcurl8.19.0affected
curlcurl8.18.0affected
curlcurl8.17.0affected

Weaknesses

  • CWE-295: Improper Certificate Validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: total

Additional References

References