Critical severity9.1NVD Advisory· Published Jul 3, 2026· Updated Jul 7, 2026
CVE-2026-11564
CVE-2026-11564
Description
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup.
An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.
Affected products
13- osv-coords11 versionspkg:apk/chainguard/eco-python-curlpkg:apk/chainguard/eco-python-curl-minimalpkg:apk/chainguard/eco-python-curl-minimal-binpkg:apk/chainguard/eco-python-curl-minimal-devpkg:apk/chainguard/eco-python-curl-minimal-docpkg:apk/chainguard/eco-python-curl-minimal-staticpkg:apk/chainguard/eco-python-curl-nghttp2pkg:apk/chainguard/eco-python-curl-nghttp2-binpkg:apk/chainguard/eco-python-curl-nghttp2-devpkg:apk/chainguard/eco-python-curl-nghttp2-staticpkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweed
< 8.21.0-r0+ 10 more
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-1.1
Patches
Vulnerability mechanics
References
3- curl.se/docs/CVE-2026-11564.htmlnvdPatchVendor Advisory
- hackerone.com/reports/3788984nvdExploitIssue TrackingThird Party Advisory
- curl.se/docs/CVE-2026-11564.jsonnvdVendor Advisory
News mentions
1- 25-Year-Old Vulnerability in cURL Used by 30 Billion Devices Finally PatchedCyber Security News · Jun 25, 2026