Description


libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.

Related CPE's


Vulnerable

References




https://hackerone.com/reports/3788984

ExploitIssue TrackingThird Party Advisory

https://hackerone.com/reports/3788984

ExploitIssue TrackingThird Party Advisory

Weaknesses


2499f714-1537-4658-8207-48ae4bb9eae9

Secondary

CWE-295


CWE-295

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

9.1 · Critical

Information


Source identifier

2499f714-1537-4658-8207-48ae4bb9eae9

Vulnerability status

Modified

Published

2026-07-03T07:16:23.790Z

3 months ago

Last modified

2026-09-15T07:16:25.530Z

3 weeks ago