Junglewise Threat Intelligence

CVE-2026-9546: curl libcurl information exposure via persistent Referer header

CVE-2026-9546 · Severity: info · Published 2026-07-03

Technologies: Curl.

Executive brief

A vulnerability in the libcurl library, which is widely used by applications to transfer data over the internet, could cause sensitive information to be leaked. When an application attempts to clear the 'Referer' header (which tracks the previous webpage visited), the library fails to do so and instead sends the old information to subsequent servers. This could result in private URLs or session data being shared with unintended third parties.

Technical details

A flaw in libcurl's handling of the CURLOPT_REFERER option prevents the internal state from being cleared when a NULL value is passed. According to documentation, passing NULL should suppress the header; however, the library erroneously reuses the previous referrer string in subsequent requests. This is classified as an information exposure (CWE-200). The issue affects libcurl versions 8.18.0 through 8.20.0 and is fixed in version 8.21.0. The curl command-line tool is not affected.

Affected products

  • curl curl 8.18.0 to 8.20.0

Timeline

  • 2026-05-22: disclosed: Reported to the curl project via HackerOne
  • 2026-06-24: patched: Fixed in version 8.21.0
  • 2026-06-24: advisory: Project curl security advisory published
  • 2026-07-03: other: NVD publication date

References