Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-390

JLSEC-2026-390

JLSEC Published
Modified
Affected Packages
CURL_jll < 8.5.0+0
LibCURL_jll < 7.83.1+0
Aliases / Upstream
CVE-2022-27781

libcurl provides the CURLOPT_CERTINFO option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.

References