With the wolfSSL backend, when CA caching is enabled and an
CURLOPT_SSL_CTX_FUNCTION callback replaces the trust store, libcurl can
silently reinstall the cached store after the callback returns. A certificate
trusted by the cached store but rejected by the callback-selected store is
then incorrectly accepted.
{
"URL": "https://curl.se/docs/CVE-2026-82208.json",
"CWE": {
"desc": "Improper Certificate Validation",
"id": "CWE-295"
},
"package": "curl",
"affects": "lib",
"last_affected": "8.21.0",
"www": "https://curl.se/docs/CVE-2026-82208.html",
"severity": "Low",
"issue": "https://hackerone.com/reports/3973090"
}[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"3923404689551009163607441279828111175",
"297624718997870639840150836257476086448",
"56205908250059361441879990564662064602",
"85439685350400643831478693185264849405",
"206455418915853995366232742870540736875",
"308268091786777598060810704004673016972",
"317513464329706427293671634178034016553",
"69518472294264634418027510581645809159",
"72674729481011985343164199229800799409",
"194300608716949252276030240923330874213",
"81827856355291595232907156722595705799"
],
"threshold": 0.9
},
"id": "CURL-CVE-2026-82208-004be86c",
"target": {
"file": "lib/vtls/wolfssl.c"
},
"source": "https://github.com/curl/curl.git/commit/ed0338befd1d865a8ea1fbaa90013a096dedd07a",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1763.0,
"function_hash": "39676463464626033682420662062357537373"
},
"id": "CURL-CVE-2026-82208-790f655b",
"target": {
"function": "wssl_init_ech",
"file": "lib/vtls/wolfssl.c"
},
"source": "https://github.com/curl/curl.git/commit/ed0338befd1d865a8ea1fbaa90013a096dedd07a",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2147.0,
"function_hash": "1807422166572413733492374297762200315"
},
"id": "CURL-CVE-2026-82208-9159197f",
"target": {
"function": "wssl_populate_x509_store",
"file": "lib/vtls/wolfssl.c"
},
"source": "https://github.com/curl/curl.git/commit/ed0338befd1d865a8ea1fbaa90013a096dedd07a",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 973.0,
"function_hash": "128549031654971917451338542360004250539"
},
"id": "CURL-CVE-2026-82208-9a967e5c",
"target": {
"function": "Curl_wssl_setup_x509_store",
"file": "lib/vtls/wolfssl.c"
},
"source": "https://github.com/curl/curl.git/commit/ed0338befd1d865a8ea1fbaa90013a096dedd07a",
"signature_version": "v1"
}
]
"https://curl.se/docs/CURL-CVE-2026-82208.json"
"2026-09-03T02:01:57Z"