Junglewise Threat Intelligence

CVE-2026-5773: libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that

CVE-2026-5773 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: Haxx Curl. Vendors: Haxx.

Executive brief

A vulnerability in the curl library, which is widely used by applications to transfer data, could cause the software to reuse the wrong network connection when communicating with file servers. This flaw occurs when using the SMB protocol and could result in an application downloading the wrong file or uploading sensitive data to an unintended folder on the same server. This could lead to unauthorized data exposure or the corruption of files on corporate network shares.

Technical details

A logical error in libcurl's connection pooling mechanism fails to validate the 'share' name when attempting to reuse an existing SMB(S) connection. While the library correctly matches the server name and credentials, it ignores the specific share path, allowing a subsequent request intended for one share to be executed over a connection established for another. This vulnerability (CWE-488) affects curl versions 7.40.0 through 8.19.0. An attacker or an unlucky sequence of application requests could result in files being read from or written to the wrong location. The issue is resolved in version 8.20.0 by disabling SMB connection reuse entirely.

Affected products

  • haxx curl 7.40.0 to 8.19.0

Timeline

  • 2026-04-05: disclosed: Reported to the curl project
  • 2026-04-29: patched: Fixed in version 8.20.0
  • 2026-05-13: advisory: NVD publication date

References

Related threats