Exposure of Data Element to Wrong Session in cURL - CVE-2026-80231

 

Exposure of Data Element to Wrong Session in cURL - CVE-2026-80231

Published: September 2, 2026


Vulnerability identifier: #VU146680
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80231
CWE-ID: CWE-488
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass intended certificate validation settings.

The vulnerability exists due to exposure of data element to wrong session in HTTPS connection reuse logic when reusing an existing connection for the same hostname with a different native CA store setting. A remote user can cause a transfer to use a previously established HTTPS connection to bypass intended certificate validation settings.

This issue affects Windows and macOS and also impacts the curl command line tool.


Affected software

cURL

How to mitigate CVE-2026-80231

Install security update from vendor's website.

cURL - update to 8.22.0

External References

Related Security Bulletins