Security Advisory

CVE-2022-27782

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-06-01 00:00:00
Last updated 2026-05-27 13:33:52
Assigner hackerone
State PUBLISHED

Description

libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.