CVE 7.5 HIGH

wrong reuse of SMB connection_CVE-2026-5773

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

libcurl might in some circumstances reuse the wrong connection for SMB(S)
transfers.

libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.

When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a network transfer operation that was requested by an
application could wrongfully reuse an existing SMB connection to the same
server that was using a different 'share' than the new subsequent transfer
should.

This could in unlucky situations lead to the download of the wrong file or the
upload of a file to the wrong place. When this happens, the same credentials
are used and the server name is the same.

Basic Information

ID CVE-2026-5773
Source curl
Published May 13, 2026 at 08:27
Modified May 13, 2026 at 17:45

Affected Product

Vendor curl
Product curl
Version 8.19.0
Affected Versions curl curl 8.19.0
curl curl 8.18.0
curl curl 8.17.0
curl curl 8.16.0
curl curl 8.15.0
curl curl 8.14.1
curl curl 8.14.0
curl curl 8.13.0
curl curl 8.12.1
curl curl 8.12.0
curl curl 8.11.1
curl curl 8.11.0
curl curl 8.10.1
curl curl 8.10.0
curl curl 8.9.1
curl curl 8.9.0
curl curl 8.8.0
curl curl 8.7.1
curl curl 8.7.0
curl curl 8.6.0
curl curl 8.5.0
curl curl 8.4.0
curl curl 8.3.0
curl curl 8.2.1
curl curl 8.2.0
curl curl 8.1.2
curl curl 8.1.1
curl curl 8.1.0
curl curl 8.0.1
curl curl 8.0.0
curl curl 7.88.1
curl curl 7.88.0
curl curl 7.87.0
curl curl 7.86.0
curl curl 7.85.0
curl curl 7.84.0
curl curl 7.83.1
curl curl 7.83.0
curl curl 7.82.0
curl curl 7.81.0
curl curl 7.80.0
curl curl 7.79.1
curl curl 7.79.0
curl curl 7.78.0
curl curl 7.77.0
curl curl 7.76.1
curl curl 7.76.0
curl curl 7.75.0
curl curl 7.74.0
curl curl 7.73.0
curl curl 7.72.0
curl curl 7.71.1
curl curl 7.71.0
curl curl 7.70.0
curl curl 7.69.1
curl curl 7.69.0
curl curl 7.68.0
curl curl 7.67.0
curl curl 7.66.0
curl curl 7.65.3
curl curl 7.65.2
curl curl 7.65.1
curl curl 7.65.0
curl curl 7.64.1
curl curl 7.64.0
curl curl 7.63.0
curl curl 7.62.0
curl curl 7.61.1
curl curl 7.61.0
curl curl 7.60.0
curl curl 7.59.0
curl curl 7.58.0
curl curl 7.57.0
curl curl 7.56.1
curl curl 7.56.0
curl curl 7.55.1
curl curl 7.55.0
curl curl 7.54.1
curl curl 7.54.0
curl curl 7.53.1
curl curl 7.53.0
curl curl 7.52.1
curl curl 7.52.0
curl curl 7.51.0
curl curl 7.50.3
curl curl 7.50.2
curl curl 7.50.1
curl curl 7.50.0
curl curl 7.49.1
curl curl 7.49.0
curl curl 7.48.0
curl curl 7.47.1
curl curl 7.47.0
curl curl 7.46.0
curl curl 7.45.0
curl curl 7.44.0
curl curl 7.43.0
curl curl 7.42.1
curl curl 7.42.0
curl curl 7.41.0
curl curl 7.40.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.