Executive brief
curl is a widely-used library for transferring data over the internet, including secure LDAP connections. When using curl in multi-threaded applications, changing TLS settings (like certificate verification) in one thread could unintentionally affect other concurrent connections in different threads, potentially disabling security protections globally. An attacker with ability to influence TLS settings could weaken or disable encryption verification for other users' connections.
Technical details
This vulnerability exists in libcurl's legacy (non-Windows) LDAP backend implementation when performing LDAPS (LDAP over TLS) transfers concurrently across multiple threads. The root cause is unsynchronized access to shared TLS configuration state (CWE-567): when one thread modifies TLS options such as certificate verification settings, these changes propagate globally rather than remaining isolated to that thread's transfer. This affects only builds using the legacy LDAP support (lib/ldap.c); OpenLDAP and WinLDAP backends are not vulnerable. The vulnerability is highly timing-sensitive as the global state is only used during connection setup. An attacker with the ability to configure LDAPS connections in one thread could manipulate TLS verification for concurrent transfers in other threads. The vulnerability was fixed in curl 8.18.0 (released 2026-01-07) and also in maintenance releases 8.16.1 and 8.14.2.
Affected products
- curl curl 7.17.0 to 8.17.0 (with exceptions: fixed in 8.18.0, 8.16.1, 8.14.2)
Timeline
- 2026-01-07: disclosed: Security advisory published on curl.se
- 2026-01-07: patched: curl 8.18.0 released with fix
- 2025-12-01: other: Vulnerability reported to curl project