A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (CURLSSLOPT_NATIVE_CA) than when the connection was created.
CURLSSLOPT_NATIVE_CA
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-80231.json"