{"cvss":7.5,"datePublished":"2026-07-03T07:16:25.807","dateUpdated":"2026-09-15T07:16:34.947","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation.","id":"CVE-2026-9545","raw":{"affected":[{"affectedData":[{"defaultStatus":"unaffected","product":"curl","vendor":"curl","versions":[{"lessThan":"8.14.2","status":"affected","version":"8.11.0","versionType":"semver"},{"lessThan":"8.16.1","status":"affected","version":"8.15.0","versionType":"semver"},{"lessThan":"8.20.1","status":"affected","version":"8.17.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"curl","repo":"https://github.com/curl/curl.git","vendor":"curl","versions":[{"lessThan":"7b9613fa9b1a5e04301a3920eef58e8138dad05e","status":"affected","version":"962097b8dd44ed5b9e7984bc1cdffdbdd566857f","versionType":"git"}]},{"defaultStatus":"unaffected","product":"curl","vendor":"curl","versions":[{"status":"affected","version":"8.20.0"},{"status":"affected","version":"8.19.0"},{"status":"affected","version":"8.18.0"},{"status":"affected","version":"8.17.0"},{"status":"affected","version":"8.16.0"},{"status":"affected","version":"8.15.0"},{"status":"affected","version":"8.14.1"},{"status":"affected","version":"8.14.0"},{"status":"affected","version":"8.13.0"},{"status":"affected","version":"8.12.1"},{"status":"affected","version":"8.12.0"},{"status":"affected","version":"8.11.1"},{"status":"affected","version":"8.11.0"}]}],"source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"configurations":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*","matchCriteriaId":"C6D1007D-3E09-4D44-993A-9ACC2316FD0A","versionEndExcluding":"8.21.0","versionStartIncluding":"8.11.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"cveTags":[],"descriptions":[{"lang":"en","value":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation."}],"id":"CVE-2026-9545","lastModified":"2026-09-15T07:16:34.947","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"exploitabilityScore":3.9,"impactScore":3.6,"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2026-9545","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-06T16:52:42.898546Z","version":"2.0.3"}}]},"published":"2026-07-03T07:16:25.807","references":[{"source":"2499f714-1537-4658-8207-48ae4bb9eae9","tags":["Patch","Vendor Advisory"],"url":"https://curl.se/docs/CVE-2026-9545.html"},{"source":"2499f714-1537-4658-8207-48ae4bb9eae9","tags":["Vendor Advisory"],"url":"https://curl.se/docs/CVE-2026-9545.json"},{"source":"2499f714-1537-4658-8207-48ae4bb9eae9","tags":["Exploit","Issue Tracking","Third Party Advisory"],"url":"https://hackerone.com/reports/3752888"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Issue Tracking","Third Party Advisory"],"url":"https://hackerone.com/reports/3752888"}],"sourceIdentifier":"2499f714-1537-4658-8207-48ae4bb9eae9","vulnStatus":"Modified","weaknesses":[{"description":[{"lang":"en","value":"CWE-200"}],"source":"2499f714-1537-4658-8207-48ae4bb9eae9","type":"Secondary"},{"description":[{"lang":"en","value":"NVD-CWE-noinfo"}],"source":"nvd@nist.gov","type":"Primary"}]},"severity":"HIGH","source":"nvd","title":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second tra..."}