CVE-2026-11564Disclosure(haxx / curl)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - libcurl connection pool CA trust confusion (CVE-2026-11564) libcurl can incorrectly reuse a previously established connection from its connection pool when an easy handle’s TLS configuration changes, causing the wrong CA trust settings to be applied on a later transfer. The root cause is improper state isolation/input validation around connection reuse, where trust store/CA material changes on the same handle are not consistently enforced for pooled connections. An attacker can exploit this when they can influence or intercept outbound TLS connections (e.g., on-path/MITM scenarios) and the application reuses an easy handle that was reconfigured from native CA trust to custom CA material (or vice versa). Impact is unintended trust decisions that can enable TLS interception, credential/session theft, and data exfiltration despite the application believing it pinned or constrained trust for subsequent requests. 👉 Affected: libcurl (versions not yet specified) | Upgrade to No fix yet - treat as suspicious

    Post summary

    The post announces CVE‑2026‑11564, detailing how libcurl’s connection pool can lead to incorrect CA trust and potential TLS interception, without providing PoC, exploit tools, or patches.

    0000088
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more