GHSA-2xgv-7q8p-67gcHighCVSS 7.5

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer...

Published
September 6, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (1)

📋 Description

When CURLOPT_PINNEDPUBLICKEY is configured alongside options that disable standard peer verification (CURLOPT_SSL_VERIFYPEER = 0 and CURLOPT_SSL_VERIFYHOST = 0), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.

🔗 References (5)