CVE-2026-11564: Native CA trust persist
Published Jul 3, 2026
·Updated
Last updated 10 July 2026
Other sources
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup.
— Launchpad
Affected Software
3 affected componentsFixes available
libcurl=
haxx curl>=8.17.0<8.21.0
debian/curl<=8.20.0-5
7.74.0-1.3+deb11u137.74.0-1.3+deb11u167.88.1-10+deb12u147.88.1-10+deb12u58.14.1-2+deb13u38.21.0-2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 7.74.0-1.3+deb11u13Fixed in 7.74.0-1.3+deb11u16Fixed in 7.88.1-10+deb12u14Fixed in 7.88.1-10+deb12u5Fixed in 8.14.1-2+deb13u3Fixed in 8.21.0-2
Event History
Jul 3, 2026
CVE Published
via MITRE·06:12 AM
Data Sourced
via MITRE·06:12 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 9, 2026
Data Sourced
via Debian·09:52 PM
DescriptionAffected Software
Data Sourced
via Launchpad·09:52 PM
Description
Jul 11, 2026
Data Sourced
via Ubuntu·09:54 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-11564?
CVE-2026-11564 is considered critical with a severity score of 9.1.
2
How can CVE-2026-11564 affect my application?
CVE-2026-11564 allows an application to continue trusting the native platform CA store even after switching to a custom CA, leading to potential security risks.
3
What software is affected by CVE-2026-11564?
The vulnerability CVE-2026-11564 affects the libcurl library.
4
How do I fix CVE-2026-11564?
To mitigate CVE-2026-11564, ensure that you are using a version of libcurl that addresses this vulnerability.
5
When was CVE-2026-11564 published?
CVE-2026-11564 was published on July 3, 2026.