Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11564

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.

A flaw was found in curl. When libcurl reuses a connection from its connection pool, an easy handle that initially used default native Certificate Authority (CA) trust may continue to trust the native platform store. This occurs even after the application has switched that same handle to custom CA material for a subsequent transfer, potentially bypassing intended certificate validation.

Отчет

This Moderate flaw in curl allows a certificate validation bypass. When libcurl reuses a connection, an application that switches from default native CA trust to custom CA material on the same handle may inadvertently continue to trust the native platform store. This could lead to a bypass of intended certificate validation, as the custom CA material might not be correctly applied, potentially allowing connections to untrusted endpoints.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9Under investigation
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Under investigation
Red Hat Enterprise Linux 10curlNot affected
Red Hat Enterprise Linux 10igvmUnder investigation
Red Hat Enterprise Linux 10rustUnder investigation
Red Hat Enterprise Linux 10s390utilsUnder investigation
Red Hat Enterprise Linux 10snphostUnder investigation
Red Hat Enterprise Linux 10trusteeUnder investigation
Red Hat Enterprise Linux 10trustee-guest-componentsUnder investigation
Red Hat Enterprise Linux 6curlNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2496754libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse

EPSS

Процентиль: 29%
0.00363
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 1 месяца назад

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.

CVSS3: 9.1
nvd
около 1 месяца назад

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.

CVSS3: 9.1
debian
около 1 месяца назад

libcurl keeps previously used connections in a connection pool for sub ...

CVSS3: 9.1
github
около 1 месяца назад

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.

CVSS3: 4.8
fstec
2 месяца назад

Уязвимость библиотеки libcurl программного средства для взаимодействия с серверами cURL, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю осуществить подмену данных или получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 29%
0.00363
Низкий

6.5 Medium

CVSS3