Beveiligingsadvies

CVE-2026-82208

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-06 17:49:16
Laatst bijgewerkt 2026-09-15 06:03:14
Toegewezen door curl
CVSS-score 7.5
Status PUBLISHED

Beschrijving

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached store but rejected by the callback-selected store is then incorrectly accepted.