When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on
connections established without a presented server certificate. Bypassing the
pinning check under these disabled-verification conditions allows
unauthenticated connections to succeed when they should be rejected.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sun, 06 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Curl
Curl curl |
|
| Vendors & Products |
Curl
Curl curl |
Sun, 06 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-295 |
Sun, 06 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected. | |
| Title | OpenSSL pinning bypass | |
| References |
|
Status: PUBLISHED
Assigner: curl
Published: 2026-09-06T17:48:16.262Z
Updated: 2026-09-08T18:53:26.975Z
Reserved: 2026-08-26T04:24:25.568Z
Link: CVE-2026-80230
Updated: 2026-09-08T18:53:14.829Z
Status : Undergoing Analysis
Published: 2026-09-06T18:17:22.327
Modified: 2026-09-08T19:19:54.063
Link: CVE-2026-80230
No data.