CVE-2026-11564
קריטית 9.1
תיאור (מקור, אנגלית)
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.
מדדים
- CVSS 3.1
-
9.1 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-15/8/2026
- CWE
- CWE-295
מוצרים מושפעים
haxx: curl
קישורים
- https://curl.se/docs/CVE-2026-11564.html PatchVendor Advisory
- https://curl.se/docs/CVE-2026-11564.json Vendor Advisory
- https://hackerone.com/reports/3788984 ExploitIssue TrackingThird Party Advisory
- https://hackerone.com/reports/3788984 ExploitIssue TrackingThird Party Advisory