CVE-2026-9545

Aliases:DEBIAN-CVE-2026-9545ALPINE-CVE-2026-9545CGA-68x5-p62m-2qhgCGA-6w5g-gw87-qqp6CGA-775g-q67h-3m8xCGA-7jv6-65h2-gqfvCGA-9g9p-j5gv-f2w2CGA-9rc4-g6fj-c43cCGA-gp36-j62j-7x53CGA-gv7w-c29w-vw8xCGA-hw66-828v-85j8CGA-hx29-q5xh-36fcCGA-jm94-7qc5-2fqxCGA-mxgm-9c5w-gqx2CGA-p6fm-p5mv-pqjhCGA-q9rv-c626-xcchCGA-qvr2-9pcr-hjjgCGA-rr2m-8wv4-9pvjCGA-w6r4-6jmj-rg4jCGA-x63r-6hwf-chx7CGA-x6j9-fhcr-xgpxCGA-xw85-p3h4-q7fg
Modified
Published: 03 Jul 2026, 06:17
Last modified:15 Sept 2026, 06:03

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.27% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

03 Jul 2026, 06:17
Published
Vulnerability first disclosed
15 Sept 2026, 06:03
Last Modified
Vulnerability information updated

Description

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.27% Percentile: 19%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • alpinecurl

    ≥ 8.11.0, < 8.22.0-r0 | ≥ 8.11.0, < 8.21.0-r0

  • chainguardeco-python-curl

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal-bin

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal-dev

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal-doc

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal-static

    < 8.21.0-r0

  • chainguardeco-python-curl-nghttp2

    < 8.21.0-r0

  • chainguardeco-python-curl-nghttp2-bin

    < 8.21.0-r0

  • chainguardeco-python-curl-nghttp2-dev

    < 8.21.0-r0

  • chainguardeco-python-curl-nghttp2-static

    < 8.21.0-r0

  • curlcurl

    8.20.0 | 8.19.0 | 8.18.0 | 8.17.0 | 8.16.0 | 8.15.0 | 8.14.1 | 8.14.0 | 8.13.0 | 8.12.1 | 8.12.0 | 8.11.1 | 8.11.0 | ≥ 8.11.0, < 8.14.2 | ≥ 8.15.0, < 8.16.1 | ≥ 8.17.0, < 8.20.1 | ≥ 962097b8dd44ed5b9e7984bc1cdffdbdd566857f, < 7b9613fa9b1a5e04301a3920eef58e8138dad05e | 8.20.0 | 8.19.0 | 8.18.0 | 8.17.0 | 8.16.0 | 8.15.0 | 8.14.1 | 8.14.0 | 8.13.0 | 8.12.1 | 8.12.0 | 8.11.1 | 8.11.0

  • debiancurl

    all | < 8.21.0~rc2-1

  • haxxcurl

    ≥ 8.11.0, < 8.21.0

References (7)