CVE-2026-11352
published 2026-07-03CVE-2026-11352: An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.01%
59.1th percentile
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server
to trigger a remote denial of service against a curl or libcurl client.
Because the helper function discards zero-length UDP datagrams before counting
them toward the per-call packet budget, a connected QUIC peer can continuously
stream empty datagrams to indefinitely stall the client.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 8.18.0 – 8.18.0 | — |
| curl | curl | 8.19.0 – 8.19.0 | — |
| curl | curl | 8.20.0 – 8.20.0 | — |
| devspaces | code-rhel9 | — | — |
| haxx | curl | — | — |
| haxx | curl | >= 8.18.0 < 8.21.0 | 8.21.0 |
| rhtpa | rhtpa-trustification-service-rhel9 | — | — |
| rust-lang | rust | — | — |
| ubuntu | curl | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
vendor_ubuntu3.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client.
ghsa_unreviewed·2026-07-03
CVE-2026-11352 An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client.
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server
to trigger a remote denial of service against a curl or libcurl client.
Because the helper function discards zero-length UDP datagrams before counting
them toward the per-call packet budget, a connected QUIC peer can continuously
stream empty datagrams to indefinitely stall the client.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-07-09·CVSS 3.4
CVE-2026-11352 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Harry Sintonen discovered that curl incorrectly handled credentials when
following HTTP redirects in conjunction with .netrc files. An attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
(CVE-2024-11053)
Hiroki Kurosawa discovered that curl incorrectly handled OCSP stapling
responses. A remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2024-8096)
Joshua Rogers discovered that curl had a use-after-free vulnerability when
resetting and cleaning up HTTP/2 stream handles. An attacker could possibly
use this issue
Red Hat
curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability
vendor_redhat·2026-07-03·CVSS 7.5
CVE-2026-11352 [HIGH] CWE-835 curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability
curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server
to trigger a remote denial of service against a curl or libcurl client.
Because the helper function discards zero-length UDP datagrams before counting
them toward the per-call packet budget, a connected QUIC peer can continuously
stream empty datagrams to indefinitely stall the client.
A flaw was found in curl and libcurl. A malicious HTTP/3 server can exploit an issue in the QUIC UDP receive function by continuously streaming empty UDP datagrams. This can lead to a remote denial of service (DoS) against a curl or libcurl client, as the helper function discards zero-length UDP datagrams before counting them toward
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-11352 davix: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability [epel-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-11352 [HIGH] CVE-2026-11352 davix: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability [epel-all]
CVE-2026-11352 davix: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server
to trigger a remote denial of service against a curl or libcurl client.
Because the helper function discards zero-length UDP datagrams before counting
them toward the per-call packet budget, a connected QUIC peer can continuously
stream empty datagrams to indefinitely stall the client.
Bugzilla
CVE-2026-11352 rpi-imager: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability [fedora-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-11352 [HIGH] CVE-2026-11352 rpi-imager: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability [fedora-all]
CVE-2026-11352 rpi-imager: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server
to trigger a remote denial of service against a curl or libcurl client.
Because the helper function discards zero-length UDP datagrams before counting
them toward the per-call packet budget, a connected QUIC peer can continuously
stream empty datagrams to indefinitely stall the client.
Bugzilla
CVE-2026-11352 mingw-curl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability [fedora-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-11352 [HIGH] CVE-2026-11352 mingw-curl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability [fedora-all]
CVE-2026-11352 mingw-curl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server
to trigger a remote denial of service against a curl or libcurl client.
Because the helper function discards zero-length UDP datagrams before counting
them toward the per-call packet budget, a connected QUIC peer can continuously
stream empty datagrams to indefinitely stall the client.
Bugzilla
CVE-2026-11352 curl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability [fedora-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-11352 [HIGH] CVE-2026-11352 curl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability [fedora-all]
CVE-2026-11352 curl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server
to trigger a remote denial of service against a curl or libcurl client.
Because the helper function discards zero-length UDP datagrams before counting
them toward the per-call packet budget, a connected QUIC peer can continuously
stream empty datagrams to indefinitely stall the client.
Bugzilla
CVE-2026-11352 curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability
bugzilla·2026-07-03·CVSS 7.5
CVE-2026-11352 [HIGH] CVE-2026-11352 curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability
CVE-2026-11352 curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server
to trigger a remote denial of service against a curl or libcurl client.
Because the helper function discards zero-length UDP datagrams before counting
them toward the per-call packet budget, a connected QUIC peer can continuously
stream empty datagrams to indefinitely stall the client.
2026-07-03
Published