CVE-2026-11352

Summary

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

Affected Software

VendorProductVersion RangeStatus
curlcurl8.18.0 < 8.20.1affected
curlcurl6a3d0b6d631d5e9bec797306b5b41a9f440a088d < 56eca2afb4806f1032872fa97d1834b3c1385276affected
curlcurl8.20.0affected
curlcurl8.19.0affected
curlcurl8.18.0affected

Weaknesses

  • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

Additional References

References