CVE-2026-80231
cURL vulnerability analysis and mitigation

Overview

CVE-2026-80231 is a connection reuse flaw in curl/libcurl dubbed "native CA store conn reuse," where libcurl incorrectly reuses an existing HTTPS connection established for a given hostname even when a different Native CA Store setting (CURLSSLOPT_NATIVE_CA) is in use compared to when the connection was originally created. It affects curl versions 7.71.0 through 8.21.0 (inclusive) on Windows and macOS only; versions prior to 7.71.0 and 8.22.0 or later are not affected. The vulnerability was reported on August 24, 2026, and disclosed alongside the release of curl 8.22.0 on September 2, 2026. It carries a severity rating of Low and is classified under CWE-488 (curl Advisory, oss-sec).

Technical details

The root cause is classified as CWE-488 (Exposure of Data Element to Wrong Session): libcurl's connection reuse logic fails to account for differences in the CURLSSLOPT_NATIVE_CA flag between an existing pooled connection and a new transfer request. When a connection is reused despite a mismatched Native CA Store setting, the TLS trust/verification behavior of the new transfer may be governed by the CA configuration of the original connection rather than the intended one. The flaw was introduced in commit 148534db57dda611cf8516e9 and is present only on Windows and macOS, where native CA store integration is relevant. A fix was applied in commit 7be1e70cb6bcd83e130ecf (curl Advisory).

Impact

Exploitation of this vulnerability can result in incorrect TLS certificate trust/verification behavior, potentially allowing a connection to proceed with a different (possibly weaker or unintended) CA trust anchor than the application intended. This could expose sensitive data transmitted over HTTPS to interception or man-in-the-middle attacks in scenarios where the native CA store setting is deliberately varied between transfers. The impact is limited to Windows and macOS platforms and is rated Low severity, suggesting exploitation requires specific conditions and does not directly enable arbitrary code execution (curl Advisory).

Exploitability

No public exploit code or evidence of in-the-wild exploitation has been reported for CVE-2026-80231. The CVE status was listed as "Reserved" at the time of Feedly ingestion, and the curl project rates the severity as Low, indicating limited practical exploitability. Exploitation would require an attacker to influence or observe HTTPS connections in a context where an application varies its CURLSSLOPT_NATIVE_CA setting across transfers sharing a connection pool. No CISA KEV listing or threat actor attribution has been identified (curl Advisory, Aisle Research Blog).

Mitigation and workarounds

The recommended remediation is to upgrade curl and libcurl to version 8.22.0 or later, released September 2, 2026. If upgrading immediately is not possible, applying the upstream patch (commit 7be1e70cb6bcd83e130ecf) and rebuilding is the next best option. As a temporary workaround, enabling CURLOPT_FORBID_REUSE for any transfers that use the native CA store will prevent the vulnerable connection reuse behavior (curl Advisory).

Community reactions

The vulnerability was discovered and reported by Stanislav Fort of Aisle Research, which published a blog post noting they found six curl CVEs — a contrast highlighted against AI tools (OpenAI and Anthropic) that reportedly found zero (Aisle Research Blog). The curl project lead Daniel Stenberg authored the patch and announced the release of curl 8.22.0 on his blog (Daniel Stenberg Blog). Community reaction has been relatively muted given the Low severity rating.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

curl

Fixed

sid

curl

Fixed

trixie

curl

Fixed

Ubuntu

Unknown

bionic (esm-infra)

curl

Not Affected

devel

curl

Not Affected

focal (esm-infra)

curl

Not Affected

jammy

curl

Not Affected

noble

curl

Not Affected

resolute

curl

Not Affected

trusty (esm-infra-legacy)

curl

Not Affected

xenial (esm-infra-legacy)

curl

Not Affected

Alpine

Fixed

edge

curl: 8.22.0-r0

Fixed

v3.23

curl: 8.22.0-r0

Fixed

SourceThis report was generated using AI

Related cURL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-82209HIGH8.2
  • cURL logocURL
  • curl
NoYesSep 06, 2026
CVE-2026-82208HIGH7.5
  • cURL logocURL
  • seal-curl
NoYesSep 06, 2026
CVE-2026-80255HIGH7.5
  • cURL logocURL
  • curl
NoYesSep 06, 2026
CVE-2026-80231HIGH7.5
  • cURL logocURL
  • seal-curl
NoYesSep 06, 2026
CVE-2026-80230HIGH7.5
  • cURL logocURL
  • curl-fish-completion
NoYesSep 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management