CVE-2026-82208 is a high-severity (CVSS 3.1 base 7.5) certificate-validation vulnerability in libcurl’s wolfSSL TLS backend.
What the vulnerability does
Per curl’s own advisory, when using the wolfSSL backend with CA caching enabled, an application can supply a CURLOPT_SSL_CTX_FUNCTION callback to replace libcurl’s trust store with a custom one — a mechanism applications use to apply their own, typically stricter, certificate-trust logic. The flaw: after that callback returns, libcurl can silently reinstall the previously cached trust store instead of keeping the callback-selected one. A certificate that the cached store trusts but that the application’s callback deliberately rejected is then incorrectly accepted — the exact opposite of what the callback was configured to enforce.
The CVSS vector reflects a network-reachable, low-complexity flaw with an integrity impact consistent with a certificate-validation bypass, since it defeats an application’s own explicit trust customization.
What we don’t yet have
This record traces to curl’s own advisory and a HackerOne report via NVD; no CISA KEV listing or independent corroboration is present, so confidence is medium.
Why this matters
Applications go out of their way to implement a CURLOPT_SSL_CTX_FUNCTION callback specifically because the default trust store isn’t sufficient for their security requirements — pinning to a private CA, rejecting a specific certificate, or implementing custom validation logic. A bug that silently reverts to the cached store after the callback runs means that custom logic can be quietly bypassed without any indication to the application that its own validation decision was overridden. Any application using wolfSSL with CA caching and a custom trust-store callback should confirm its libcurl version against curl’s fix.
Frequently Asked Questions
What is CVE-2026-82208?
A CVSS 7.5 high-severity vulnerability in libcurl’s wolfSSL backend where a custom trust store set via a CURLOPT_SSL_CTX_FUNCTION callback can be silently overridden by a cached store, accepting certificates the callback rejected.
Is CVE-2026-82208 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.