A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup
for a given hostname even when using a different Native CA Store setting
(CURLSSLOPT_NATIVE_CA) than when the connection was created.
{
"cna_assigner": "curl",
"cwe_ids": [
"CWE-488"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80231.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "7.71.0"
},
{
"fixed": "8.14.2"
},
{
"introduced": "8.15.0"
},
{
"fixed": "8.16.1"
},
{
"introduced": "8.17.0"
},
{
"fixed": "8.20.1"
},
{
"introduced": "148534db57dda611cf8516e92e4d6e35fc1e5074"
},
{
"fixed": "7be1e70cb6bcd83e130ecfe8cb91b6a7dcdeff42"
}
],
"source": "AFFECTED_FIELD"
}
]
}