Information disclosure in cURL - CVE-2026-9546

 

Information disclosure in cURL - CVE-2026-9546

Published: June 24, 2026


Vulnerability identifier: #VU135088
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9546
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in the libcurl HTTP Referer header handling when processing subsequent HTTP requests after CURLOPT_REFERER is cleared with NULL. A remote attacker can receive a subsequent request that erroneously includes a previously configured Referer header to disclose sensitive information.

This issue affects libcurl and does not affect the curl command line tool.


Affected software

cURL
LANTIME Operating System Firmware (LTOS)

How to mitigate CVE-2026-9546

Install security update from vendor's website.

cURL - update to 8.21.0
LANTIME Operating System Firmware (LTOS) - update to 7.10.013

External References

Related Security Bulletins