libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NHaxx Curl
APPHaxx8.17.0 – 8.21.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2026-8924CRITICAL9.1PL ✓same product
Curl: obejście sprawdzania Public Suffix List przy parsowaniu cookies
CVE-2026-8925CRITICAL9.8PL ✓same product
Double-free w obsłudze SASL/GSASL w Haxx Curl (CVE-2026-8925)
CVE-2026-10536CRITICAL9.8PL ✓same product
Use-after-free w libcurl przy operacjach HTTP/2 stream-dependency
CVE-2026-11856CRITICAL9.8PL ✓same product
libcurl: błędne przekazywanie nagłówka Authorization Digest do innego hosta
CVE-2026-8926CRITICAL9.1PL ✓same product
Haxx curl: błędne użycie hasła innego użytkownika z pliku .netrc