CVE-2016-5419: Debian Linux
High severity, CVSS 7.5. EPSS: 15.1% chance of exploitation in the next 30 days.
curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.
Affected products
- Debian Debian Linux: version 8.0 only
- Haxx Libcurl: up to and including 7.50.0
- Opensuse Leap: version 42.1 only
Published 2016-08-10. Last modified 2026-06-17.