CVE-2026-9545
published 2026-07-03CVE-2026-9545: In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.41%
32.9th percentile
In this scenario, libcurl first uses a proper HTTP/3 server for the initial
transfers, and when it makes a second transfer to the same site it has been
replaced by the attacker's impostor machine - without a valid certificate.
When libcurl returns to the hostname the second time with a cached SSL session
(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the
`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might
send off the second request's bytes on that new connection *before* enforcing
the certificate verification failure. Potentially leaking sensitive
information.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 8.11.0 – 8.11.0 | — |
| curl | curl | 8.11.1 – 8.11.1 | — |
| curl | curl | 8.12.0 – 8.12.0 | — |
| curl | curl | 8.12.1 – 8.12.1 | — |
| curl | curl | 8.13.0 – 8.13.0 | — |
| curl | curl | 8.14.0 – 8.14.0 | — |
| curl | curl | 8.14.1 – 8.14.1 | — |
| curl | curl | 8.15.0 – 8.15.0 | — |
| curl | curl | 8.16.0 – 8.16.0 | — |
| curl | curl | 8.17.0 – 8.17.0 | — |
| curl | curl | 8.18.0 – 8.18.0 | — |
| curl | curl | 8.19.0 – 8.19.0 | — |
| curl | curl | 8.20.0 – 8.20.0 | — |
| haxx | curl | >= 8.11.0 < 8.21.0 | 8.21.0 |
| ubuntu | curl | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libcurl: libcurl: Information disclosure via cached SSL session and early data
vendor_redhat·2026-07-03·CVSS 7.5
CVE-2026-9545 [HIGH] CWE-295 libcurl: libcurl: Information disclosure via cached SSL session and early data
libcurl: libcurl: Information disclosure via cached SSL session and early data
In this scenario, libcurl first uses a proper HTTP/3 server for the initial
transfers, and when it makes a second transfer to the same site it has been
replaced by the attacker's impostor machine - without a valid certificate.
When libcurl returns to the hostname the second time with a cached SSL session
(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the
`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might
send off the second request's bytes on that new connection *before* enforcing
the certificate verification failure. Potentially leaking sensitive
information.
A flaw was found in libcurl. An attacker can exploit this by replacing a legitimate HTTP/3 server with
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-06-30
CVE-2026-8286 curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Andrew Nesbitt discovered that curl could reuse an existing live
connection during STARTTLS-based connection upgrades even when the TLS
configuration did not match. A remote attacker could possibly use this
issue to cause curl to use an unintended TLS configuration.
(CVE-2026-8286)
Muhamad Arga Reksapati discovered that curl incorrectly reused
connections for Negotiate-authenticated requests when different services
were involved. A remote attacker could possibly use this issue to access
resources authenticated for another service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458)
It was discovered that curl i
GHSA
In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - wi
ghsa_unreviewed·2026-07-03
CVE-2026-9545 In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - wi
In this scenario, libcurl first uses a proper HTTP/3 server for the initial
transfers, and when it makes a second transfer to the same site it has been
replaced by the attacker's impostor machine - without a valid certificate.
When libcurl returns to the hostname the second time with a cached SSL session
(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the
`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might
send off the second request's bytes on that new connection *before* enforcing
the certificate verification failure. Potentially leaking sensitive
information.
VulDB
curl libcURL up to 8.20.0 Certificate information disclosure (EUVD-2026-41493 / WID-SEC-2026-2052)
vuldb·2026-07-03
CVE-2026-9545 [LOW] curl libcURL up to 8.20.0 Certificate information disclosure (EUVD-2026-41493 / WID-SEC-2026-2052)
A vulnerability categorized as problematic has been discovered in curl libcURL up to 8.20.0. This affects an unknown function of the component Certificate Handler. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-9545. The attack can be executed remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-9545 davix: libcurl: Information disclosure via cached SSL session and early data [epel-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-9545 [HIGH] CVE-2026-9545 davix: libcurl: Information disclosure via cached SSL session and early data [epel-all]
CVE-2026-9545 davix: libcurl: Information disclosure via cached SSL session and early data [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In this scenario, libcurl first uses a proper HTTP/3 server for the initial
transfers, and when it makes a second transfer to the same site it has been
replaced by the attacker's impostor machine - without a valid certificate.
When libcurl returns to the hostname the second time with a cached SSL session
(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the
`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might
send off the s
Bugzilla
CVE-2026-9545 libcurl: libcurl: Information disclosure via cached SSL session and early data
bugzilla·2026-07-03·CVSS 7.5
CVE-2026-9545 [HIGH] CVE-2026-9545 libcurl: libcurl: Information disclosure via cached SSL session and early data
CVE-2026-9545 libcurl: libcurl: Information disclosure via cached SSL session and early data
In this scenario, libcurl first uses a proper HTTP/3 server for the initial
transfers, and when it makes a second transfer to the same site it has been
replaced by the attacker's impostor machine - without a valid certificate.
When libcurl returns to the hostname the second time with a cached SSL session
(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the
`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might
send off the second request's bytes on that new connection *before* enforcing
the certificate verification failure. Potentially leaking sensitive
information.
Bugzilla
CVE-2026-53268 kernel: netfilter: conntrack_irc: fix possible out-of-bounds read
bugzilla·2026-06-25
CVE-2026-53268 [MEDIUM] CVE-2026-53268 kernel: netfilter: conntrack_irc: fix possible out-of-bounds read
CVE-2026-53268 kernel: netfilter: conntrack_irc: fix possible out-of-bounds read
In the Linux kernel, the following vulnerability has been resolved:
netfilter: conntrack_irc: fix possible out-of-bounds read
When parsing fails after we've matched the command string we
should bail out instead of trying to match a different command.
This helper should be deprecated, given prevalence of TLS I doubt it has
any relevance in 2026.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026062517-CVE-2026-53268-9545@gregkh/T
2026-07-03
Published