CVE-2026-4873General(haxx / curl)

MEDIUMCVSS 5.9 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch haxx curl systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.

5.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-319CWE-295

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-30); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-04-29: 1Mentions · 2026-04-30: 2Mentions · 2026-05-02: 1Mentions · 2026-06-17: 1Mentions · 2026-07-13: 1PoC Mentioned / Linked · 2026-05-02: 1Active Exploitation · 2026-06-17: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-02: 1Technical Details · 2026-06-17: 1Technical Details · 2026-07-13: 104-2904-3005-0206-1707-13
Signal classification4 categories
General
233.3%
Patch
233.3%
Disclosure
116.7%
Active Exploitation
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-291
General1
2026-04-302
General1Patch1
2026-05-021
Disclosure1
2026-06-171
Active Exploitation1
2026-07-131
Patch1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Patch

    8 CVEs fixed in curl https://www.openwall.com/lists/oss-security/2026/04/29/ CVE-2026-4873: connection reuse ignores TLS requirement CVE-2026-5545: wrong reuse of HTTP Negotiate connection CVE-2026-5773: wrong reuse of SMB connection CVE-2026-6429: netrc credential leak with reused proxy connection 1/2

    Post summary

    The text announces that eight CVEs have been fixed in the curl library, providing brief technical descriptions but no exploit details or active exploitation reports.

    12070495
    4.7K followersView on X
  • H1 Disclosed - Public Disclosures@h1Disclosed
    Disclosure

    ⚡ CVE-2026-4873: connection reuse ignores TLS requirement 👨🏻‍💻 bonaire ➟ curl 🟨 Low 💰 None 🔗 https://hackerone.com/reports/3621851 #bugbounty #bugbountytips #cybersecurity #infosec https://t.co/kkfuBnDKUY

    Post summary

    The tweet discloses CVE‑2026‑4873, a low‑severity vulnerability where connection reuse ignores the TLS requirement, and links to a HackerOne report for additional details.

    00020402
    10.2K followersView on X
  • TECHEPAGES@techepages
    Patch

    9 curl CVEs patched in Debian 13.6 🚨 🔵 CVE-2026-3783/6253 – token & credential leaks on redirects 🔵 CVE-2026-3805/5773 – SMB UAF & wrong reuse 🔵 CVE-2026-1965/5545 – Negotiate auth bypass 🔵 CVE-2026-3784 – proxy auth bypass (CVSS 6.5) 🔵 CVE-2026-6276 – cookie leak 🔵 CVE-2026-4873 – TLS bypass apt upgrade ⬆️

    Post summary

    Debian 13.6 releases patches for nine curl CVEs, providing brief technical details for each and encouraging an "apt upgrade".

    0000064
    19 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Active Exploitation

    Threat actors are exploiting MS Teams' QUIC relays for covert C2, hiding traffic & risking data integrity. Plus, new Windows TLS flaw (CVE-2026-4873) exposes sensitive data in plaintext. Patch now! #Cybersecurity #Geopolitics #InfoSec

    Post summary

    The post warns that threat actors are actively exploiting MS Teams’ QUIC relays and a Windows TLS flaw (CVE-2026-4873), urging users to patch immediately.

    0000073
    14 followersView on X
  • Autumn Good@autumn_good_35
    General

    curlで8件の脆弱性 CVE-2026-7168 CVE-2026-7009 CVE-2026-6429 CVE-2026-6276 CVE-2026-6253 CVE-2026-5773 CVE-2026-5545 CVE-2026-4873 Published vulnerabilities for curl/libcurl https://curl.se/docs/security.html

    Post summary

    The post lists eight newly disclosed CVEs related to curl/libcurl and links to the official security page, without offering exploitation details, mitigations, or further technical information.

    00000396
    6.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4873 [ADVISORY] curl https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4873

    Post summary

    The advisory merely references the CVE and URLs without providing additional vulnerability or exploit information.

    0000035
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more