Skip to main content
QUIETLYTIC
Vulnerability

curl Vulnerability (CVE-2026-80231)

CVE-2026-80231 is a CVSS 7.5 high-severity connection-reuse flaw where libcurl reuses an HTTPS connection across different Native CA Store settings.

CVE-2026-80231
Threat Level
HIGH
CVSS
7.5
Status
Monitored
Confidence
Medium
Affected Products
curl, libcurl

CVE-2026-80231 is a high-severity (CVSS 3.1 base 7.5) connection-reuse vulnerability in libcurl — the third connection-reuse bug in this CVE family alongside CVE-2026-19931 (Negotiate authentication reuse) and CVE-2026-80231 itself, both stemming from libcurl’s connection-pooling cache key not accounting for a security-relevant setting.

What the vulnerability does

Per curl’s own advisory, libcurl wrongly reuses an existing HTTPS connection for a given hostname even when a subsequent request specifies a different CURLSSLOPT_NATIVE_CA (Native CA Store) setting than the one used when the original connection was created. Since the Native CA Store setting determines which certificate authorities are trusted for that connection, reusing a connection established under a different trust configuration means a request believes it’s validating against one CA store while actually riding on a connection validated against another.

The CVSS vector reflects a network-reachable, low-complexity flaw with an integrity impact consistent with a request’s TLS trust assumptions being silently violated by connection reuse.

What we don’t yet have

This record traces to curl’s own advisory and a HackerOne report via NVD; no CISA KEV listing or independent corroboration is present, so confidence is medium.

Why this matters

Applications that toggle CURLSSLOPT_NATIVE_CA between requests to the same host — for example, switching between a system trust store and a custom CA bundle for different security contexts — are the ones exposed here, since libcurl’s connection cache doesn’t treat that setting as part of what makes two connections “the same.” Any application relying on per-request Native CA Store configuration should confirm its libcurl version against curl’s fix.

Frequently Asked Questions

What is CVE-2026-80231? A CVSS 7.5 high-severity vulnerability in libcurl where an HTTPS connection is wrongly reused across requests with different Native CA Store trust settings.

Is CVE-2026-80231 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 curl.se

Related intelligence


Analyst tools