cbcvebase.
CVE-2026-4873
published 2026-05-13

CVE-2026-4873: A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial…

PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.26%
17.5th percentile
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.

Affected

152 ranges· showing 25
VendorProductVersion rangeFixed in
build-of-trusteetrustee-rhel9
confidential-compute-attestation-tech-previewtrustee-rhel9
confidential-containerstrustee
curlcurl7.20.0 – 7.20.0
curlcurl7.20.1 – 7.20.1
curlcurl7.21.0 – 7.21.0
curlcurl7.21.1 – 7.21.1
curlcurl7.21.2 – 7.21.2
curlcurl7.21.3 – 7.21.3
curlcurl7.21.4 – 7.21.4
curlcurl7.21.5 – 7.21.5
curlcurl7.21.6 – 7.21.6
curlcurl7.21.7 – 7.21.7
curlcurl7.22.0 – 7.22.0
curlcurl7.23.0 – 7.23.0
curlcurl7.23.1 – 7.23.1
curlcurl7.24.0 – 7.24.0
curlcurl7.25.0 – 7.25.0
curlcurl7.26.0 – 7.26.0
curlcurl7.27.0 – 7.27.0
curlcurl7.28.0 – 7.28.0
curlcurl7.28.1 – 7.28.1
curlcurl7.29.0 – 7.29.0
curlcurl7.30.0 – 7.30.0
curlcurl7.31.0 – 7.31.0

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.