High severity7.5NVD Advisory· Published Jul 3, 2026· Updated Jul 7, 2026
CVE-2026-11352
CVE-2026-11352
Description
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.
Affected products
13- osv-coords11 versionspkg:apk/chainguard/eco-python-curlpkg:apk/chainguard/eco-python-curl-minimalpkg:apk/chainguard/eco-python-curl-minimal-binpkg:apk/chainguard/eco-python-curl-minimal-devpkg:apk/chainguard/eco-python-curl-minimal-docpkg:apk/chainguard/eco-python-curl-minimal-staticpkg:apk/chainguard/eco-python-curl-nghttp2pkg:apk/chainguard/eco-python-curl-nghttp2-binpkg:apk/chainguard/eco-python-curl-nghttp2-devpkg:apk/chainguard/eco-python-curl-nghttp2-staticpkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweed
< 8.21.0-r0+ 10 more
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-1.1
Patches
Vulnerability mechanics
References
3- curl.se/docs/CVE-2026-11352.htmlnvdPatchVendor Advisory
- hackerone.com/reports/3783438nvdExploitIssue TrackingThird Party Advisory
- curl.se/docs/CVE-2026-11352.jsonnvdVendor Advisory
News mentions
1- 25-Year-Old Vulnerability in cURL Used by 30 Billion Devices Finally PatchedCyber Security News · Jun 25, 2026