CVE-2026-80230
published 2026-09-06CVE-2026-80230: When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.37%
28.8th percentile
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on
connections established without a presented server certificate. Bypassing the
pinning check under these disabled-verification conditions allows
unauthenticated connections to succeed when they should be rejected.
Affected
109 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
vendor_ubuntu7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-09-24·CVSS 7.4
CVE-2026-80229 [HIGH] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for
LDAP authentication in certain circumstances. A machine-in-the-middle
attacker could possibly use this issue to bypass peer validation. This
issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-13608)
Stephan Zeisberg discovered that curl incorrectly handled HTTP/2 Server
Push streams when sharing connections between handles. A remote attacker
could possibly use this issue to cause curl to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2026-18924)
Stanislav Fort discovered that curl incorrectly managed the lifetime of
pooled TLS connections when using the multi interface. An attacker could
pos
Red Hat
curl: curl: Public key pinning bypass allows unauthenticated connections
vendor_redhat·2026-09-06·CVSS 7.5
CVE-2026-80230 [HIGH] CWE-303 curl: curl: Public key pinning bypass allows unauthenticated connections
curl: curl: Public key pinning bypass allows unauthenticated connections
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on
connections established without a presented server certificate. Bypassing the
pinning check under these disabled-verification conditions allows
unauthenticated connections to succeed when they should be rejected.
A flaw was found in libcurl, a client-side URL transfer library. When public key pinning is configured, but standard peer verification is explicitly disabled, libcurl incorrectly allows connections to proceed without enforcing the public key pinning. This bypass enables unauthenticated connection
GHSA
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public
ghsa_unreviewed·2026-09-06
CVE-2026-80230 When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on
connections established without a presented server certificate. Bypassing the
pinning check under these disabled-verification conditions allows
unauthenticated connections to succeed when they should be rejected.
VulDB
curl libcurl up to 8.21.0 certificate validation (EUVD-2026-72168)
vuldb·2026-09-06
CVE-2026-80230 [LOW] curl libcurl up to 8.21.0 certificate validation (EUVD-2026-72168)
A vulnerability was found in curl libcurl. It has been rated as problematic. This issue affects some unknown processing. This manipulation causes improper certificate validation.
The identification of this vulnerability is CVE-2026-80230. It is possible to initiate the attack remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-80230 mingw-curl: curl: Public key pinning bypass allows unauthenticated connections [fedora-all]
bugzilla·2026-09-21·CVSS 7.5
CVE-2026-80230 [HIGH] CVE-2026-80230 mingw-curl: curl: Public key pinning bypass allows unauthenticated connections [fedora-all]
CVE-2026-80230 mingw-curl: curl: Public key pinning bypass allows unauthenticated connections [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on
connections established without a presented server certificate. Bypassing the
pinning check under these disabled-verification conditions allows
unauthenticated connections to succeed when they should be rejected.
Bugzilla
CVE-2026-80230 curl: curl: Public key pinning bypass allows unauthenticated connections [fedora-all]
bugzilla·2026-09-21·CVSS 7.5
CVE-2026-80230 [HIGH] CVE-2026-80230 curl: curl: Public key pinning bypass allows unauthenticated connections [fedora-all]
CVE-2026-80230 curl: curl: Public key pinning bypass allows unauthenticated connections [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on
connections established without a presented server certificate. Bypassing the
pinning check under these disabled-verification conditions allows
unauthenticated connections to succeed when they should be rejected.
Bugzilla
CVE-2026-80230 curl: curl: Public key pinning bypass allows unauthenticated connections
bugzilla·2026-09-06·CVSS 7.5
CVE-2026-80230 [HIGH] CVE-2026-80230 curl: curl: Public key pinning bypass allows unauthenticated connections
CVE-2026-80230 curl: curl: Public key pinning bypass allows unauthenticated connections
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on
connections established without a presented server certificate. Bypassing the
pinning check under these disabled-verification conditions allows
unauthenticated connections to succeed when they should be rejected.
2026-09-06
Published