Medium severity5.9NVD Advisory· Published May 13, 2026· Updated May 14, 2026
CVE-2026-4873
CVE-2026-4873
Description
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.openwall.com/lists/oss-security/2026/04/29/7nvdMailing ListPatchThird Party Advisory
- curl.se/docs/CVE-2026-4873.htmlnvdPatchVendor Advisory
- hackerone.com/reports/3621851nvdExploitIssue TrackingThird Party Advisory
- curl.se/docs/CVE-2026-4873.jsonnvdVendor Advisory
News mentions
0No linked articles in our index yet.