Skip to main content
QUIETLYTIC
Vulnerability

curl Vulnerability (CVE-2026-82208)

CVE-2026-82208 is a CVSS 7.5 high-severity flaw where libcurl silently reinstalls a cached wolfSSL trust store after a CURLOPT_SSL_CTX_FUNCTION callback replaces it, accepting certificates the callback should have rejected.

CVE-2026-82208
Threat Level
HIGH
CVSS
7.5
Status
Monitored
Confidence
Medium
Affected Products
curl, libcurl (wolfSSL backend)

CVE-2026-82208 is a high-severity (CVSS 3.1 base 7.5) certificate-validation vulnerability in libcurl’s wolfSSL TLS backend.

What the vulnerability does

Per curl’s own advisory, when using the wolfSSL backend with CA caching enabled, an application can supply a CURLOPT_SSL_CTX_FUNCTION callback to replace libcurl’s trust store with a custom one — a mechanism applications use to apply their own, typically stricter, certificate-trust logic. The flaw: after that callback returns, libcurl can silently reinstall the previously cached trust store instead of keeping the callback-selected one. A certificate that the cached store trusts but that the application’s callback deliberately rejected is then incorrectly accepted — the exact opposite of what the callback was configured to enforce.

The CVSS vector reflects a network-reachable, low-complexity flaw with an integrity impact consistent with a certificate-validation bypass, since it defeats an application’s own explicit trust customization.

What we don’t yet have

This record traces to curl’s own advisory and a HackerOne report via NVD; no CISA KEV listing or independent corroboration is present, so confidence is medium.

Why this matters

Applications go out of their way to implement a CURLOPT_SSL_CTX_FUNCTION callback specifically because the default trust store isn’t sufficient for their security requirements — pinning to a private CA, rejecting a specific certificate, or implementing custom validation logic. A bug that silently reverts to the cached store after the callback runs means that custom logic can be quietly bypassed without any indication to the application that its own validation decision was overridden. Any application using wolfSSL with CA caching and a custom trust-store callback should confirm its libcurl version against curl’s fix.

Frequently Asked Questions

What is CVE-2026-82208? A CVSS 7.5 high-severity vulnerability in libcurl’s wolfSSL backend where a custom trust store set via a CURLOPT_SSL_CTX_FUNCTION callback can be silently overridden by a cached store, accepting certificates the callback rejected.

Is CVE-2026-82208 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 curl.se

Related intelligence


Analyst tools