CyberRota Analysis
AI-GeneratedA vulnerability in libcurl allows for the improper reuse of an existing HTTPS connection for a hostname, even when a different Native CA Store setting is specified. This flaw could lead to potential man-in-the-middle attacks, as it may expose sensitive data or allow unauthorized access to resources. Organizations using libcurl in their applications should prioritize addressing this issue to mitigate security risks associated with improper connection handling.
Original NVD Description
A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.
Related CVEs
Other vulnerabilities affecting the same vendor(s)