CVE-2026-80230
Dashboard / Vulnerabilities / CVE-2026-80230
CVE-2026-80230
Summary: OpenSSL pinning bypass
Details: When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.
References: https://curl.se/docs/CVE-2026-80230.html, https://curl.se/docs/CVE-2026-80230.json, https://hackerone.com/reports/3969300, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80230.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80230, https://github.com/curl/curl.git
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
