7.5

CVE-2026-80231

Exploit

native CA store conn reuse

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup
for a given hostname even when using a different Native CA Store setting
(`CURLSSLOPT_NATIVE_CA`) than when the connection was created.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haxx ≫ Curl Version >= 7.71.0 < 8.22.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.119
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-488 Exposure of Data Element to Wrong Session

The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.

https://curl.se/docs/CVE-2026-80231.json
Vendor Advisory
https://curl.se/docs/CVE-2026-80231.html
Patch
Vendor Advisory
Mitigation
https://hackerone.com/reports/3969368
Third Party Advisory
Exploit
Mitigation