Description


libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.

Related CPE's


Vulnerable

References




https://hackerone.com/reports/3733910

ExploitIssue TrackingThird Party Advisory

https://hackerone.com/reports/3733910

ExploitIssue TrackingThird Party Advisory

Weaknesses


2499f714-1537-4658-8207-48ae4bb9eae9

Secondary

CWE-305


NVD-CWE-Other

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.5 · High

Information


Source identifier

2499f714-1537-4658-8207-48ae4bb9eae9

Vulnerability status

Modified

Published

2026-07-03T07:16:25.363Z

3 months ago

Last modified

2026-09-15T07:16:33.407Z

3 weeks ago