CVE-2026-11564

Published: July 2, 2026Last modified: July 6, 2026

Description

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.

Severity score breakdown

ParameterValue
Base score9.1
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTScurlFixed (8.21.0-r0)
25 LTScurlFixed (8.21.0-r0)
StreamcurlFixed (8.21.0-r0)
Hardened ContainersStreamcurlFixed (8.21.0-r0)

References

ON THIS PAGE