← Back to CVE List
CVE-2026-61813NVD
Vulnerability Summary
Summary Incorrect libcurl TLS hostname verification setting in HttpsClient::download Details File: src/utils/https_client.cc Location: curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 1); Reference: https://github.com/owasp-modsecurity/ModSecurity/blob/f5a6fcd37aea3a7618408b7d1f03b94de9164637/src/utils/https_client.cc#L99 Summary: The code sets CURLOPT_SSL_VERIFYHOST to 1, which is not the recommended strict hostname verification mode in libcurl. The secure value is 2L. Recommendation: Update: ``` curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 1); ``` to: ``` curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 2L); ``` PoC A practical proof-of-concept would require an adversary-in-the-middle (AITM/MITM) position and TLS interception conditions, which makes end-to-end exploitation non-trivial in typical environments. Impact Using a non-strict/incorrect hostname verification setting can weaken TLS peer identity validation and may increase risk of accepting certificates for unintended hosts (MITM risk).
CVSS v3.1 Base Metrics — Score 3.7
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- ModSecurity all version
Not provided by Private for this CVE.