PT-2026-51741 · Libcurl+2 · Libcurl+2

·

CVE-2026-11564

·

Published

2026-06-05

·

Updated

2026-08-11

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions libcurl (affected versions not specified)
Description An issue exists in the certificate authentication procedure where the library maintains a connection pool for reusing connections in subsequent transfers. If a handle initially uses the default native CA trust and is later switched to custom CA material, it may continue to trust the native platform store for subsequent transfers using that handle. This could allow a remote attacker to perform data spoofing or gain unauthorized access to protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08699
CVE-2026-11564
JLSEC-2026-1199
OPENSUSE-SU-2026:11230-1
RHSA-2026:34975
USN-8525-1

Affected Products

Linuxmint
Ubuntu
Libcurl