Flaw in libcurl Allows Improper HTTPS Connection Reuse
CVE-2026-80231

Currently unrated

Key Information:

Vendor

Curl

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-80231?

A flaw in libcurl results in the incorrect reuse of an existing HTTPS connection associated with a specific hostname. This occurs even when using a different Native CA Store setting (CURLSSLOPT_NATIVE_CA) from that of the original connection establishment. As a result, this vulnerability may expose systems to potential security risks by enabling the misuse of trusted connections under varied CA configurations.

Affected Version(s)

curl 8.21.0

curl 8.20.0

curl 8.19.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stanislav Fort (Aisle Research)
Daniel Stenberg
.