CVE-2026-11564
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.
- Haxx Curl
- < 8.21.0
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 0.4% (29th percentile)
- Weakness
- CWE-295
- NVD status
- Analyzed
- Published
- 2026-07-03
CVE-2026-11564 at NVD
No indexed exploits for CVE-2026-11564 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-11564 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.