UBUNTU-CVE-2026-80230
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-80230
UBUNTU-CVE-2026-80230
Summary:
Details: When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.
References: https://ubuntu.com/security/CVE-2026-80230, https://www.cve.org/CVERecord?id=CVE-2026-80230, https://curl.se/docs/CVE-2026-80230.html, https://github.com/curl/curl/commit/5267ed859d545534d0c21, https://ubuntu.com/security/notices/USN-8820-1
Affected packages
Package
Name: curl
Purl: pkg:deb/ubuntu/curl?arch=source&distro=esm-infra-legacy%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
