UNKNOWN NVD
CVE-2026-82208
With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cac
With the wolfSSL backend, when CA caching is enabled and an
`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can
silently reinstall the cached store after the callback returns. A certificate
trusted by the cached store but rejected by the callback-selected store is
then incorrectly accepted.
References
- https://curl.se/docs/CVE-2026-82208.html
- https://curl.se/docs/CVE-2026-82208.json
- https://hackerone.com/reports/3973090
This unknown severity vulnerability was published on 2026-09-06 via NVD.
vulnfeed aggregates 9982 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.