CVE-2026-80230
OpenSSL pinning bypass
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.
| CWE | CWE-295 |
| Vendor | curl |
| Product | curl |
| Published | Sep 6, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for curl curl
Be the first to know when new high vulnerabilities affecting curl curl are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
curl / curl
7.45.0 < 8.14.2 8.15.0 < 8.16.1 8.17.0 < 8.20.1 8.21.0 < 8.22.0
curl / curl
8363656cb4e0c60a11d8531ead0ec43120b50591 < 5267ed859d545534d0c21675a2b70af5a3b6e3ef
curl / curl
8.21.0 8.20.0 8.19.0 8.18.0 8.17.0 8.16.0 8.15.0 8.14.1 8.14.0 8.13.0 8.12.1 8.12.0 8.11.1 8.11.0 8.10.1 8.10.0 8.9.1 8.9.0 8.8.0 8.7.1 8.7.0 8.6.0 8.5.0 8.4.0 8.3.0 8.2.1 8.2.0 8.1.2 8.1.1 8.1.0 8.0.1 8.0.0 7.88.1 7.88.0 7.87.0 7.86.0 7.85.0 7.84.0 7.83.1 7.83.0 7.82.0 7.81.0 7.80.0 7.79.1 7.79.0 7.78.0 7.77.0 7.76.1 7.76.0 7.75.0 7.74.0 7.73.0 7.72.0 7.71.1 7.71.0 7.70.0 7.69.1 7.69.0 7.68.0 7.67.0 7.66.0 7.65.3 7.65.2 7.65.1 7.65.0 7.64.1 7.64.0 7.63.0 7.62.0 7.61.1 7.61.0 7.60.0 7.59.0 7.58.0 7.57.0 7.56.1 7.56.0 7.55.1 7.55.0 7.54.1 7.54.0 7.53.1 7.53.0 7.52.1 7.52.0 7.51.0 7.50.3 7.50.2 7.50.1 7.50.0 7.49.1 7.49.0 7.48.0 7.47.1 7.47.0 7.46.0 7.45.0
References
Credits
Stanislav Fort (Aisle Research) Daniel Stenberg