CVE-2026-9546

Summary

A vulnerability in libcurl caused the HTTP Referer: header to persist even when explicitly cleared. While the documentation states that passing NULL to CURLOPT_REFERER suppresses the header, the option failed to clear the internal state. As a result, the previous referrer string was erroneously reused and sent in subsequent requests, potentially leaking sensitive information to unintended servers.

Affected Software

VendorProductVersion RangeStatus
curlcurl8.18.0 < 8.20.1affected
curlcurl2cb868242dc2ac9cd52ee64987ef51d5964a56f9 < 862e8a74a84478d82973471b4f49dc2746c1780eaffected
curlcurl8.20.0affected
curlcurl8.19.0affected
curlcurl8.18.0affected

Weaknesses

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

Additional References

References