Skip to main content
QUIETLYTIC
Vulnerability

curl Certificate Pinning Bypass (CVE-2026-80230)

CVE-2026-80230 is a CVSS 7.5 high-severity flaw where libcurl skips public-key-pinning enforcement on connections without a presented server certificate when standard peer verification is disabled.

CVE-2026-80230
Threat Level
HIGH
CVSS
7.5
Status
Monitored
Confidence
Medium
Affected Products
curl, libcurl

CVE-2026-80230 is a high-severity (CVSS 3.1 base 7.5) certificate-pinning bypass in libcurl.

What the vulnerability does

Per curl’s own advisory, when an application configures CURLOPT_PINNEDPUBLICKEY (public-key pinning) alongside options that disable standard peer verification (CURLOPT_SSL_VERIFYPEER = 0 and CURLOPT_SSL_VERIFYHOST = 0), libcurl fails to enforce the pinning check on connections established without a presented server certificate at all. The intent of pinning in this configuration is typically to provide a minimal trust check even when full certificate-chain verification is deliberately disabled (a pattern some applications use for pinned, self-managed TLS endpoints) — but under these specific conditions, that fallback check doesn’t happen, allowing an unauthenticated connection to succeed when it should be rejected outright.

The CVSS vector reflects a network-reachable, low-complexity flaw with an integrity impact consistent with a man-in-the-middle succeeding against a connection the application believed was still protected by key pinning.

What we don’t yet have

This record traces to curl’s own advisory and a HackerOne report via NVD; no CISA KEV listing or independent corroboration is present, so confidence is medium.

Why this matters

This is a narrow but meaningful configuration gap: applications that deliberately disable standard peer/host verification and rely on CURLOPT_PINNEDPUBLICKEY as their sole remaining trust check are exactly the ones exposed — and that combination exists specifically because developers wanted some TLS validation while skipping the standard chain check, so the failure defeats the one protection they were actually relying on. Any application using this exact configuration pattern should confirm its libcurl version against curl’s fix.

Frequently Asked Questions

What is CVE-2026-80230? A CVSS 7.5 high-severity vulnerability in libcurl where public-key pinning is not enforced on connections lacking a presented server certificate, when standard peer/host verification is also disabled.

Is CVE-2026-80230 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 curl.se

Related intelligence


Analyst tools