๐Ÿ” CVE Alert

CVE-2026-82208

HIGH 7.5

wolfSSL CA-cache hit overrides callback

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached store but rejected by the callback-selected store is then incorrectly accepted.

CWE CWE-295
Vendor curl
Product curl
Published Sep 6, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for curl curl

Be the first to know when new high vulnerabilities affecting curl curl are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

curl / curl
8.9.1 < 8.14.2 8.15.0 < 8.16.1 8.17.0 < 8.20.1 8.21.0 < 8.22.0
curl / curl
0f2876b2c33f6784a27b6f7345bd8cd95b46352a < ed0338befd1d865a8ea1fbaa90013a096dedd07a
curl / curl
8.21.0 8.20.0 8.19.0 8.18.0 8.17.0 8.16.0 8.15.0 8.14.1 8.14.0 8.13.0 8.12.1 8.12.0 8.11.1 8.11.0 8.10.1 8.10.0 8.9.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
curl.se: https://curl.se/docs/CVE-2026-82208.json curl.se: https://curl.se/docs/CVE-2026-82208.html hackerone.com: https://hackerone.com/reports/3973090

Credits

Stanislav Fort (Aisle Research) Stefan Eissing