CVE-2026-3805Disclosure(haxx / curl)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch haxx curl systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • Peaked 6d ago at 3 mentions (2026-03-11); latest day: 1
  • 12 total mentions across 7 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline12 mentions / 7d
01223Mentions · 2026-03-11: 3Mentions · 2026-03-12: 2Mentions · 2026-03-13: 2Mentions · 2026-03-15: 2Mentions · 2026-03-16: 1Mentions · 2026-03-18: 1Mentions · 2026-07-13: 1PoC Mentioned / Linked · 2026-03-11: 1PoC Mentioned / Linked · 2026-03-15: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 2Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-12: 2Technical Details · 2026-03-15: 2Technical Details · 2026-03-18: 1Technical Details · 2026-07-13: 103-1103-1203-1303-1503-1603-1807-13
Signal classification4 categories
Disclosure
541.7%
Patch
541.7%
PoC
18.3%
General
18.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-113
Disclosure2PoC1
2026-03-122
Disclosure1Patch1
2026-03-132
Patch2
2026-03-152
Disclosure2
2026-03-161
General1
2026-03-181
Patch1
2026-07-131
Patch1
Full discourse12 posts
  • H1 Disclosed - Public Disclosures@h1Disclosed
    Disclosure

    ⚡ CVE-2026-3805: use after free in SMB connection reuse 👨🏻‍💻 @Nadsec11 ➟ curl 🟧 Medium 💰 None 🔗 https://hackerone.com/reports/3591944 #bugbounty #bugbountytips #cybersecurity #infosec https://t.co/Baq67sRuBA

    Post summary

    The tweet announces CVE‑2026‑3805, detailing a use‑after‑free in SMB connection reuse, with a Medium severity rating and a link to a HackerOne report, but presents no active exploitation, patch, or false‑positive claim.

    021131826
    10.1K followersView on X
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    PoC

    CVE-2026-3805: use after free in SMB connection reuse https://hackerone.com/reports/3591944 #bugbounty #bugbountytips #bugbountytip

    Post summary

    A HackerOne report links a use‑after‑free flaw in SMB connection reuse (CVE‑2026‑3805) and includes a PoC, but there is no evidence of active exploitation or available patches.

    00066657
    40.3K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    4 Low to Medium CVEs fixed in curl https://www.openwall.com/lists/oss-security/2026/03/11/ CVE-2026-1965: bad reuse of HTTP Negotiate connection CVE-2026-3783: token leak with redirect and netrc CVE-2026-3784: wrong proxy connection reuse with credentials CVE-2026-3805: use after free in SMB connection reuse

    Post summary

    The post announces that four low‑to‑medium severity CVEs have been fixed in curl, providing short technical details for each but no mention of PoC, exploits, or active attacks.

    00063792
    4.4K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-curl モジュール更新情報 8.19.0-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 curl 8.19.0-1 この更新には脆弱性(CVE-2026-3805, CVE-2026-3784, CVE-2026-3783, CVE-2026-1965)への対応が含まれます。 モジュールのアップデートについては、以下のコマンドで適用可能です。 # ... https://kusanagi.tokyo/releases/23348/

    Post summary

    Update to kusanagi-curl 8.19.0-1 includes fixes for CVE-2026-3805, CVE-2026-3784, CVE-2026-3783, and CVE-2026-1965.

    01010150
    198 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en cURL ❗ CVE-2026-3805 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-curl-2/ https://t.co/Kl3EdcYJFS

    Post summary

    The post announces a CVE-2026-3805 vulnerability in cURL and provides a link for additional information.

    00001120
    6.6K followersView on X
  • nad@Nadsec11
    Disclosure

    Found this bug on the weekend :) https://curl.se/docs/CVE-2026-3805.html Curl is cool. For the love of the game..

    Post summary

    The user reports finding CVE-2026-3805 and links to the official CVE page, but no further details on exploitation, patches, or technical specifics are provided.

    00010192
    305 followersView on X
  • TECHEPAGES@techepages
    Patch

    9 curl CVEs patched in Debian 13.6 🚨 🔵 CVE-2026-3783/6253 – token & credential leaks on redirects 🔵 CVE-2026-3805/5773 – SMB UAF & wrong reuse 🔵 CVE-2026-1965/5545 – Negotiate auth bypass 🔵 CVE-2026-3784 – proxy auth bypass (CVSS 6.5) 🔵 CVE-2026-6276 – cookie leak 🔵 CVE-2026-4873 – TLS bypass apt upgrade ⬆️

    Post summary

    Debian 13.6 has patched nine curl-related CVEs covering leaks and authentication bypasses; users should run apt upgrade to apply the fixes.

    0000064
    19 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 URGENT: #SUSE & #openSUSE curl update fixes 4 CVEs! 🚨 Includes CVE-2026-1965 (HTTP Negotiate bypass), token leaks (CVE-2026-3783), and a critical SMB use-after-free (CVE-2026-3805). Read more: 👉 https://tinyurl.com/yc3p8esw #Security https://t.co/UrK4inqHTv

    Post summary

    This tweet announces a curl update from SUSE/openSUSE that patches four CVEs, providing succinct technical details of each vulnerability but no exploit or PoC information.

    0000046
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3805 When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory. https://www.cve.org/CVERecord?id=CVE-2026-3805

    Post summary

    The content announces a use‑after‑free vulnerability (CVE-2026-3805) in curl’s SMB handling, providing a brief technical description but lacking evidence of exploitation, PoC, or patch information.

    00000129
    56.7K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-curl Module Update 8.19.0-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: curl 8.19.0-1 This update includes support for vulnerability(CVE-2026-3805, CVE-2026-3784, CVE-2026-3783, CVE-2026-1965). The module... https://kusanagi.tokyo/en/releases/23349/

    Post summary

    The Kusanagi curl module update 8.19.0-1 includes patches for CVE-2026-3805, CVE-2026-3784, CVE-2026-3783, and CVE-2026-1965.

    0000045
    198 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 curl, Use After Free, #CVE-2026-3805 (Medium) https://dailycve.com/curl-use-after-free-cve-2026-3805-medium/

    Post summary

    The tweet announces a medium‑severity use‑after‑free vulnerability in curl (CVE‑2026‑3805) and links to a DailyCVE article for more details.

    0000021
    167 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3805 - use after free in SMB connection reuse Intel Report: https://ift.tt/JXrkRad

    Post summary

    The tweet announces a use‑after‑free vulnerability in SMB connections (CVE‑2026‑3805) and links to an intel report, but provides no PoC, exploit, or patch details.

    0000021
    343 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more