SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-80231

HIGH · CVSS 7.5 EPSS 0.94%

Source: NVD + CISA KEV + EPSS · Published 2026-09-06 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A vulnerability in libcurl allows for the improper reuse of an existing HTTPS connection for a hostname, even when a different Native CA Store setting is specified. This flaw could lead to potential man-in-the-middle attacks, as it may expose sensitive data or allow unauthorized access to resources. Organizations using libcurl in their applications should prioritize addressing this issue to mitigate security risks associated with improper connection handling.

CVE
CVE-2026-80231
Severity
HIGH
CVSS
7.5
EPSS
0.94%

Original NVD Description

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.

Related CVEs

Other vulnerabilities affecting the same vendor(s)