Improper Certificate Validation in cURL - CVE-2026-11564
Published: June 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass certificate trust restrictions.
The vulnerability exists due to improper certificate validation in libcurl connection reuse logic when reusing an easy handle after switching from native CA trust to custom CA material. A remote attacker can present a TLS certificate trusted by the native platform store to bypass certificate trust restrictions.
This issue applies to builds that use Native CA by default on Apple operating systems or Windows, and affects the OpenSSL, GnuTLS, Schannel, and Rustls TLS backends.
Affected software
LANTIME Operating System Firmware (LTOS)
Ubuntu
openEuler
Fedora
curl (Ubuntu package)
curl-debuginfo
curl-debugsource
libcurl
libcurl-devel
curl-help
curl
How to mitigate CVE-2026-11564
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm21, 7.47.0-1ubuntu2.19+esm17, 7.58.0-2ubuntu3.24+esm10, 7.68.0-1ubuntu2.25+esm5, 8.5.0-2ubuntu10.11, 8.14.1-2ubuntu1.5, 8.18.0-1ubuntu2.3
curl-debuginfo - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-debugsource - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
libcurl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
libcurl-devel - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-help - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl - update to 8.18.0-10.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Ubuntu update for curl
- Multiple vulnerabilities in Meinberg LANTIME firmware
- openEuler 24.03 LTS SP3 update for curl
- openEuler 24.03 LTS SP1 update for curl
- openEuler 22.03 LTS SP4 update for curl
- openEuler 20.03 LTS SP4 update for curl
- Fedora 44 update for curl
- openEuler 24.03 LTS SP4 update for curl