CVE-2026-80230 is a high-severity (CVSS 3.1 base 7.5) certificate-pinning bypass in libcurl.
What the vulnerability does
Per curl’s own advisory, when an application configures CURLOPT_PINNEDPUBLICKEY (public-key pinning) alongside options that disable standard peer verification (CURLOPT_SSL_VERIFYPEER = 0 and CURLOPT_SSL_VERIFYHOST = 0), libcurl fails to enforce the pinning check on connections established without a presented server certificate at all. The intent of pinning in this configuration is typically to provide a minimal trust check even when full certificate-chain verification is deliberately disabled (a pattern some applications use for pinned, self-managed TLS endpoints) — but under these specific conditions, that fallback check doesn’t happen, allowing an unauthenticated connection to succeed when it should be rejected outright.
The CVSS vector reflects a network-reachable, low-complexity flaw with an integrity impact consistent with a man-in-the-middle succeeding against a connection the application believed was still protected by key pinning.
What we don’t yet have
This record traces to curl’s own advisory and a HackerOne report via NVD; no CISA KEV listing or independent corroboration is present, so confidence is medium.
Why this matters
This is a narrow but meaningful configuration gap: applications that deliberately disable standard peer/host verification and rely on CURLOPT_PINNEDPUBLICKEY as their sole remaining trust check are exactly the ones exposed — and that combination exists specifically because developers wanted some TLS validation while skipping the standard chain check, so the failure defeats the one protection they were actually relying on. Any application using this exact configuration pattern should confirm its libcurl version against curl’s fix.
Frequently Asked Questions
What is CVE-2026-80230? A CVSS 7.5 high-severity vulnerability in libcurl where public-key pinning is not enforced on connections lacking a presented server certificate, when standard peer/host verification is also disabled.
Is CVE-2026-80230 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.