cbcvebase.
CVE-2026-82208
published 2026-09-06

CVE-2026-82208: With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.43%
36.2th percentile
With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached store but rejected by the callback-selected store is then incorrectly accepted.

Affected

23 ranges
VendorProductVersion rangeFixed in
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl>= 0f2876b2c33f6784a27b6f7345bd8cd95b46352a < ed0338befd1d865a8ea1fbaa90013a096dedd07aed0338befd1d865a8ea1fbaa90013a096dedd07a
curlcurl>= 8.15.0 < 8.16.18.16.1
curlcurl>= 8.17.0 < 8.20.18.20.1
curlcurl>= 8.21.0 < 8.22.08.22.0
curlcurl>= 8.9.1 < 8.14.28.14.2
haxxcurl>= 8.9.1 < 8.22.08.22.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.