Security Advisory

CVE-2026-82208

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-06 17:49:16
Last updated 2026-09-15 06:03:14
Assigner curl
CVSS score 7.5
State PUBLISHED

Description

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached store but rejected by the callback-selected store is then incorrectly accepted.