Information disclosure in cURL - CVE-2026-9546
Published: June 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in the libcurl HTTP Referer header handling when processing subsequent HTTP requests after CURLOPT_REFERER is cleared with NULL. A remote attacker can receive a subsequent request that erroneously includes a previously configured Referer header to disclose sensitive information.
This issue affects libcurl and does not affect the curl command line tool.
Affected software
LANTIME Operating System Firmware (LTOS)
openEuler
Fedora
libcurl
curl
curl-debuginfo
curl-debugsource
libcurl-devel
curl-help
How to mitigate CVE-2026-9546
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
libcurl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-debuginfo - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-debugsource - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
libcurl-devel - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-help - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl - update to 8.18.0-9.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Fedora 44 update for curl
- openEuler 24.03 LTS SP3 update for curl
- openEuler 24.03 LTS SP1 update for curl
- openEuler 22.03 LTS SP4 update for curl
- openEuler 20.03 LTS SP4 update for curl
- openEuler 24.03 LTS SP4 update for curl