CVE-2026-11352

Aliases:DEBIAN-CVE-2026-11352ALPINE-CVE-2026-11352CGA-5pfc-hq45-w877CGA-5xgp-6jh6-56w7CGA-6x5w-h8ch-pj65CGA-967x-mjj3-frpqCGA-9w2p-wcw3-q6q8CGA-9w59-3229-fqc5CGA-c2q5-cxw3-wpc4CGA-chxc-836p-cf4fCGA-h68x-cq2f-6fcmCGA-hq28-qrrg-9976CGA-jcq6-qmj6-rjhhCGA-jg5q-3whg-3q3mCGA-jv5j-xgwh-2px6CGA-m5j4-xphq-r8g7CGA-r3xx-cqw9-99r8CGA-vjw9-3rqx-8f3gCGA-w2f5-wmh9-cq65CGA-wjh3-7947-hjc8CGA-x3pp-hrwj-gm3wCGA-xgm2-9vv2-w3vp
Modified
Published: 03 Jul 2026, 06:12
Last modified:15 Sept 2026, 06:02

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.71% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

03 Jul 2026, 06:12
Published
Vulnerability first disclosed
15 Sept 2026, 06:02
Last Modified
Vulnerability information updated

Description

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.71% Percentile: 52%

Techniques & Countermeasures

  • CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')

    The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Systems

  • alpinecurl

    ≥ 8.18.0, < 8.22.0-r0 | ≥ 8.18.0, < 8.21.0-r0

  • chainguardeco-python-curl

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal-bin

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal-dev

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal-doc

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal-static

    < 8.21.0-r0

  • chainguardeco-python-curl-nghttp2

    < 8.21.0-r0

  • chainguardeco-python-curl-nghttp2-bin

    < 8.21.0-r0

  • chainguardeco-python-curl-nghttp2-dev

    < 8.21.0-r0

  • chainguardeco-python-curl-nghttp2-static

    < 8.21.0-r0

  • curlcurl

    8.20.0 | 8.19.0 | 8.18.0 | ≥ 8.18.0, < 8.20.1 | ≥ 6a3d0b6d631d5e9bec797306b5b41a9f440a088d, < 56eca2afb4806f1032872fa97d1834b3c1385276 | 8.20.0 | 8.19.0 | 8.18.0

  • debiancurl

    < 8.21.0~rc2-1

  • haxxcurl

    ≥ 8.18.0, < 8.21.0

References (7)