CVE-2026-11564
9.1
CRITICAL
CVSS 3.1
EPSS 0.61%
Description
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.
How to fix CVE-2026-11564
To remediate CVE-2026-11564, upgrade the affected package to a fixed version below.
- —upgrade to 8.21.0-r0 or later
Is CVE-2026-11564 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 8.17.0, < 8.21.0-r0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |