CVE-2026-11564
published 2026-07-03CVE-2026-11564: libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first…
PriorityP348critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.61%
45.3th percentile
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup.
An easy handle that first uses default native CA trust can continue trusting
the native platform store after the application switches that same handle to
custom CA material for a later transfer.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 8.17.0 – 8.17.0 | — |
| curl | curl | 8.18.0 – 8.18.0 | — |
| curl | curl | 8.19.0 – 8.19.0 | — |
| curl | curl | 8.20.0 – 8.20.0 | — |
| haxx | curl | — | — |
| haxx | curl | >= 8.17.0 < 8.21.0 | 8.21.0 |
| ubuntu | curl | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
vendor_ubuntu3.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-07-09·CVSS 3.4
CVE-2026-11352 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Harry Sintonen discovered that curl incorrectly handled credentials when
following HTTP redirects in conjunction with .netrc files. An attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
(CVE-2024-11053)
Hiroki Kurosawa discovered that curl incorrectly handled OCSP stapling
responses. A remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2024-8096)
Joshua Rogers discovered that curl had a use-after-free vulnerability when
resetting and cleaning up HTTP/2 stream handles. An attacker could possibly
use this issue
Red Hat
libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse
vendor_redhat·2026-07-03·CVSS 9.1
CVE-2026-11564 [CRITICAL] CWE-295 libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse
libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup.
An easy handle that first uses default native CA trust can continue trusting
the native platform store after the application switches that same handle to
custom CA material for a later transfer.
A flaw was found in curl. When libcurl reuses a connection from its connection pool, an easy handle that initially used default native Certificate Authority (CA) trust may continue to trust the native platform store. This occurs even after the application has switched that same handle to custom CA material for a subsequent transfer, potentially bypassing intended certificate validation.
GHSA
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup.
ghsa_unreviewed·2026-07-03
CVE-2026-11564 libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup.
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup.
An easy handle that first uses default native CA trust can continue trusting
the native platform store after the application switches that same handle to
custom CA material for a later transfer.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-11564 davix: libcurl: Certificate validation bypass due to incorrect connection reuse [epel-all]
bugzilla·2026-07-08·CVSS 9.1
CVE-2026-11564 [CRITICAL] CVE-2026-11564 davix: libcurl: Certificate validation bypass due to incorrect connection reuse [epel-all]
CVE-2026-11564 davix: libcurl: Certificate validation bypass due to incorrect connection reuse [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup.
An easy handle that first uses default native CA trust can continue trusting
the native platform store after the application switches that same handle to
custom CA material for a later transfer.
Bugzilla
CVE-2026-11564 libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse
bugzilla·2026-07-03·CVSS 9.1
CVE-2026-11564 [CRITICAL] CVE-2026-11564 libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse
CVE-2026-11564 libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup.
An easy handle that first uses default native CA trust can continue trusting
the native platform store after the application switches that same handle to
custom CA material for a later transfer.
2026-07-03
Published