Vulnerability Details CVE-2026-82208
With the wolfSSL backend, when CA caching is enabled and an
`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can
silently reinstall the cached store after the callback returns. A certificate
trusted by the cached store but rejected by the callback-selected store is
then incorrectly accepted.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 3.2%
CVSS Severity
CVSS v3 Score 7.5