FlawAtlas
Search the atlas
CVE-2026-11564 Low

Native CA trust persist

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.

Exploit probability 0.6%
Published June 24, 2026
Required by Not available
Last source change June 24, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

16 explicit affected versions

Unknown Unknown

18 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-11564

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.

View original source
Open Source Vulnerabilities CURL-CVE-2026-11564

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.

View original source

05 / REFERENCES

Further evidence