
🚨 CRITICAL - libcurl connection pool CA trust confusion (CVE-2026-11564) libcurl can incorrectly reuse a previously established connection from its connection pool when an easy handle’s TLS configuration changes, causing the wrong CA trust settings to be applied on a later transfer. The root cause is improper state isolation/input validation around connection reuse, where trust store/CA material changes on the same handle are not consistently enforced for pooled connections. An attacker can exploit this when they can influence or intercept outbound TLS connections (e.g., on-path/MITM scenarios) and the application reuses an easy handle that was reconfigured from native CA trust to custom CA material (or vice versa). Impact is unintended trust decisions that can enable TLS interception, credential/session theft, and data exfiltration despite the application believing it pinned or constrained trust for subsequent requests. 👉 Affected: libcurl (versions not yet specified) | Upgrade to No fix yet - treat as suspicious
Post summary
The post announces CVE‑2026‑11564, detailing how libcurl’s connection pool can lead to incorrect CA trust and potential TLS interception, without providing PoC, exploit tools, or patches.
