๐Ÿ” CVE Alert

CVE-2026-80230

HIGH 7.5

OpenSSL pinning bypass

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.

CWE CWE-295
Vendor curl
Product curl
Published Sep 6, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for curl curl

Be the first to know when new high vulnerabilities affecting curl curl are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

curl / curl
7.45.0 < 8.14.2 8.15.0 < 8.16.1 8.17.0 < 8.20.1 8.21.0 < 8.22.0
curl / curl
8363656cb4e0c60a11d8531ead0ec43120b50591 < 5267ed859d545534d0c21675a2b70af5a3b6e3ef
curl / curl
8.21.0 8.20.0 8.19.0 8.18.0 8.17.0 8.16.0 8.15.0 8.14.1 8.14.0 8.13.0 8.12.1 8.12.0 8.11.1 8.11.0 8.10.1 8.10.0 8.9.1 8.9.0 8.8.0 8.7.1 8.7.0 8.6.0 8.5.0 8.4.0 8.3.0 8.2.1 8.2.0 8.1.2 8.1.1 8.1.0 8.0.1 8.0.0 7.88.1 7.88.0 7.87.0 7.86.0 7.85.0 7.84.0 7.83.1 7.83.0 7.82.0 7.81.0 7.80.0 7.79.1 7.79.0 7.78.0 7.77.0 7.76.1 7.76.0 7.75.0 7.74.0 7.73.0 7.72.0 7.71.1 7.71.0 7.70.0 7.69.1 7.69.0 7.68.0 7.67.0 7.66.0 7.65.3 7.65.2 7.65.1 7.65.0 7.64.1 7.64.0 7.63.0 7.62.0 7.61.1 7.61.0 7.60.0 7.59.0 7.58.0 7.57.0 7.56.1 7.56.0 7.55.1 7.55.0 7.54.1 7.54.0 7.53.1 7.53.0 7.52.1 7.52.0 7.51.0 7.50.3 7.50.2 7.50.1 7.50.0 7.49.1 7.49.0 7.48.0 7.47.1 7.47.0 7.46.0 7.45.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
curl.se: https://curl.se/docs/CVE-2026-80230.json curl.se: https://curl.se/docs/CVE-2026-80230.html hackerone.com: https://hackerone.com/reports/3969300

Credits

Stanislav Fort (Aisle Research) Daniel Stenberg