curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < 5ec63fdbca604568890c577753c6f66c5b3ef0b5 |