Exposure of Data Element to Wrong Session in cURL - CVE-2026-80231
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to bypass intended certificate validation settings.
The vulnerability exists due to exposure of data element to wrong session in HTTPS connection reuse logic when reusing an existing connection for the same hostname with a different native CA store setting. A remote user can cause a transfer to use a previously established HTTPS connection to bypass intended certificate validation settings.
This issue affects Windows and macOS and also impacts the curl command line tool.