CVE-2026-9546
published 2026-07-03CVE-2026-9546: A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.65%
47.0th percentile
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even
when explicitly cleared. While the documentation states that passing NULL to
`CURLOPT_REFERER` suppresses the header, the option failed to clear the
internal state. As a result the previous referrer string was erroneously
reused and sent in subsequent requests, potentially leaking sensitive
information to unintended servers.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 8.18.0 – 8.18.0 | — |
| curl | curl | 8.19.0 – 8.19.0 | — |
| curl | curl | 8.20.0 – 8.20.0 | — |
| haxx | curl | — | — |
| haxx | curl | >= 8.18.0 < 8.21.0 | 8.21.0 |
| rust-lang | rust | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libcurl: libcurl: Information disclosure due to persistent Referer header
vendor_redhat·2026-07-03·CVSS 7.5
CVE-2026-9546 [HIGH] CWE-201 libcurl: libcurl: Information disclosure due to persistent Referer header
libcurl: libcurl: Information disclosure due to persistent Referer header
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even
when explicitly cleared. While the documentation states that passing NULL to
`CURLOPT_REFERER` suppresses the header, the option failed to clear the
internal state. As a result the previous referrer string was erroneously
reused and sent in subsequent requests, potentially leaking sensitive
information to unintended servers.
A flaw was found in libcurl. This vulnerability causes the HTTP Referer header to persist even after it has been explicitly cleared. This can lead to the previous referrer string being unintentionally reused and sent in subsequent requests, potentially disclosing sensitive information to unintended servers.
Statement:
VulDB
curl libcURL up to 8.18.0/8.19.0/8.20.0 information disclosure (EUVD-2026-41494 / WID-SEC-2026-2052)
vuldb·2026-07-03
CVE-2026-9546 [LOW] curl libcURL up to 8.18.0/8.19.0/8.20.0 information disclosure (EUVD-2026-41494 / WID-SEC-2026-2052)
A vulnerability identified as problematic has been detected in curl libcURL up to 8.18.0/8.19.0/8.20.0. This impacts an unknown function. Performing a manipulation results in information disclosure.
This vulnerability is reported as CVE-2026-9546. The attack is possible to be carried out remotely. No exploit exists.
GHSA
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared.
ghsa_unreviewed·2026-07-03
CVE-2026-9546 A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared.
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even
when explicitly cleared. While the documentation states that passing NULL to
`CURLOPT_REFERER` suppresses the header, the option failed to clear the
internal state. As a result the previous referrer string was erroneously
reused and sent in subsequent requests, potentially leaking sensitive
information to unintended servers.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-9546 davix: libcurl: Information disclosure due to persistent Referer header [epel-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-9546 [HIGH] CVE-2026-9546 davix: libcurl: Information disclosure due to persistent Referer header [epel-all]
CVE-2026-9546 davix: libcurl: Information disclosure due to persistent Referer header [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even
when explicitly cleared. While the documentation states that passing NULL to
`CURLOPT_REFERER` suppresses the header, the option failed to clear the
internal state. As a result the previous referrer string was erroneously
reused and sent in subsequent requests, potentially leaking sensitive
information to unintended servers.
Bugzilla
CVE-2026-9546 libcurl: libcurl: Information disclosure due to persistent Referer header
bugzilla·2026-07-03·CVSS 7.5
CVE-2026-9546 [HIGH] CVE-2026-9546 libcurl: libcurl: Information disclosure due to persistent Referer header
CVE-2026-9546 libcurl: libcurl: Information disclosure due to persistent Referer header
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even
when explicitly cleared. While the documentation states that passing NULL to
`CURLOPT_REFERER` suppresses the header, the option failed to clear the
internal state. As a result the previous referrer string was erroneously
reused and sent in subsequent requests, potentially leaking sensitive
information to unintended servers.
2026-07-03
Published