PT-2026-51755 · Curl · Libcurl

·

CVE-2026-9546

·

Published

2026-06-24

·

Updated

2026-08-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions libcurl (affected versions not specified)
Description An issue exists where the HTTP Referer: header persists even after being explicitly cleared. Although passing NULL to CURLOPT REFERER is intended to suppress the header, the internal state is not cleared. This causes the previous referrer string to be reused and sent in subsequent requests, which may lead to the leakage of sensitive information to unintended servers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9546
JLSEC-2026-1221
OPENSUSE-SU-2026:11230-1
RHSA-2026:34975

Affected Products

Libcurl