High severity7.5NVD Advisory· Published Jul 3, 2026· Updated Jul 7, 2026
CVE-2026-9545
CVE-2026-9545
Description
In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.
When libcurl returns to the hostname the second time with a cached SSL session (CURLOPT_SSL_SESSIONID_CACHE is not disabled) and early data enabled (the CURLSSLOPT_EARLYDATA bit is set in CURLOPT_SSL_OPTIONS), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information.
Affected products
14- osv-coords12 versionspkg:apk/chainguard/eco-python-curlpkg:apk/chainguard/eco-python-curl-minimalpkg:apk/chainguard/eco-python-curl-minimal-binpkg:apk/chainguard/eco-python-curl-minimal-devpkg:apk/chainguard/eco-python-curl-minimal-docpkg:apk/chainguard/eco-python-curl-minimal-staticpkg:apk/chainguard/eco-python-curl-nghttp2pkg:apk/chainguard/eco-python-curl-nghttp2-binpkg:apk/chainguard/eco-python-curl-nghttp2-devpkg:apk/chainguard/eco-python-curl-nghttp2-staticpkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweed
< 8.21.0-r0+ 11 more
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.14.1-160000.8.1
- (no CPE)range: < 8.21.0-1.1
Patches
Vulnerability mechanics
References
3- curl.se/docs/CVE-2026-9545.htmlnvdPatchVendor Advisory
- hackerone.com/reports/3752888nvdExploitIssue TrackingThird Party Advisory
- curl.se/docs/CVE-2026-9545.jsonnvdVendor Advisory
News mentions
1- 25-Year-Old Vulnerability in cURL Used by 30 Billion Devices Finally PatchedCyber Security News · Jun 25, 2026