
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-80231 is a connection reuse flaw in curl/libcurl dubbed "native CA store conn reuse," where libcurl incorrectly reuses an existing HTTPS connection established for a given hostname even when a different Native CA Store setting (CURLSSLOPT_NATIVE_CA) is in use compared to when the connection was originally created. It affects curl versions 7.71.0 through 8.21.0 (inclusive) on Windows and macOS only; versions prior to 7.71.0 and 8.22.0 or later are not affected. The vulnerability was reported on August 24, 2026, and disclosed alongside the release of curl 8.22.0 on September 2, 2026. It carries a severity rating of Low and is classified under CWE-488 (curl Advisory, oss-sec).
The root cause is classified as CWE-488 (Exposure of Data Element to Wrong Session): libcurl's connection reuse logic fails to account for differences in the CURLSSLOPT_NATIVE_CA flag between an existing pooled connection and a new transfer request. When a connection is reused despite a mismatched Native CA Store setting, the TLS trust/verification behavior of the new transfer may be governed by the CA configuration of the original connection rather than the intended one. The flaw was introduced in commit 148534db57dda611cf8516e9 and is present only on Windows and macOS, where native CA store integration is relevant. A fix was applied in commit 7be1e70cb6bcd83e130ecf (curl Advisory).
Exploitation of this vulnerability can result in incorrect TLS certificate trust/verification behavior, potentially allowing a connection to proceed with a different (possibly weaker or unintended) CA trust anchor than the application intended. This could expose sensitive data transmitted over HTTPS to interception or man-in-the-middle attacks in scenarios where the native CA store setting is deliberately varied between transfers. The impact is limited to Windows and macOS platforms and is rated Low severity, suggesting exploitation requires specific conditions and does not directly enable arbitrary code execution (curl Advisory).
No public exploit code or evidence of in-the-wild exploitation has been reported for CVE-2026-80231. The CVE status was listed as "Reserved" at the time of Feedly ingestion, and the curl project rates the severity as Low, indicating limited practical exploitability. Exploitation would require an attacker to influence or observe HTTPS connections in a context where an application varies its CURLSSLOPT_NATIVE_CA setting across transfers sharing a connection pool. No CISA KEV listing or threat actor attribution has been identified (curl Advisory, Aisle Research Blog).
The recommended remediation is to upgrade curl and libcurl to version 8.22.0 or later, released September 2, 2026. If upgrading immediately is not possible, applying the upstream patch (commit 7be1e70cb6bcd83e130ecf) and rebuilding is the next best option. As a temporary workaround, enabling CURLOPT_FORBID_REUSE for any transfers that use the native CA store will prevent the vulnerable connection reuse behavior (curl Advisory).
The vulnerability was discovered and reported by Stanislav Fort of Aisle Research, which published a blog post noting they found six curl CVEs — a contrast highlighted against AI tools (OpenAI and Anthropic) that reportedly found zero (Aisle Research Blog). The curl project lead Daniel Stenberg authored the patch and announced the release of curl 8.22.0 on his blog (Daniel Stenberg Blog). Community reaction has been relatively muted given the Low severity rating.
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
curl
devel
curl
focal (esm-infra)
curl
jammy
curl
noble
curl
resolute
curl
trusty (esm-infra-legacy)
curl
xenial (esm-infra-legacy)
curl
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."