CVE-2026-5545Disclosure(haxx / curl)

MEDIUMCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch haxx curl systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1...

4.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-305CWE-613

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-30); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-29: 1Mentions · 2026-04-30: 2Mentions · 2026-05-02: 1Mentions · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-02: 1Exploit Tool / Code · 2026-05-02: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-02: 104-2904-3005-0205-11
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-291
General1
2026-04-302
Disclosure1Patch1
2026-05-021
Disclosure1
2026-05-111
Patch1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Patch

    8 CVEs fixed in curl https://www.openwall.com/lists/oss-security/2026/04/29/ CVE-2026-4873: connection reuse ignores TLS requirement CVE-2026-5545: wrong reuse of HTTP Negotiate connection CVE-2026-5773: wrong reuse of SMB connection CVE-2026-6429: netrc credential leak with reused proxy connection 1/2

    Post summary

    Curl has released patches for eight CVEs, addressing issues with connection reuse, credential leakage, and protocol handling.

    12070495
    4.7K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-curl モジュール更新情報 8.20.0-1 https://kusanagi.tokyo/releases/24476/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 curl 8.20.0-1 この更新には脆弱性(CVE-2026-7168, CVE-2026-7009, CVE-2026-6429, CVE-2026-6276, CVE-2026-6253, CVE-2026-5773, CVE-2026-5545, CVE-2...

    Post summary

    This release announces a patched kusanagi-curl module (8.20.0‑1) that fixes multiple CVEs; it provides no exploitation evidence or PoC, merely indicating the patch addresses the vulnerabilities.

    0101085
    200 followersView on X
  • H1 Disclosed - Public Disclosures@h1Disclosed
    Disclosure

    ⚡ CVE-2026-5545: wrong reuse of HTTP Negotiate connection 👨🏻‍💻 quaccws ➟ curl 🟧 Medium 💰 None 🔗 https://hackerone.com/reports/3642555 #bugbounty #bugbountytips #cybersecurity #infosec https://t.co/7MP5QLQuWM

    Post summary

    A researcher (quaccws) disclosed CVE-2026-5545, an issue around misusing HTTP Negotiate connections, and shared a HackerOne report; no active exploitation or patch information was provided.

    00000282
    10.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    curlで8件の脆弱性 CVE-2026-7168 CVE-2026-7009 CVE-2026-6429 CVE-2026-6276 CVE-2026-6253 CVE-2026-5773 CVE-2026-5545 CVE-2026-4873 Published vulnerabilities for curl/libcurl https://curl.se/docs/security.html

    Post summary

    The content announces that eight CVEs have been published for curl/libcurl, directing readers to the official curl security documentation, without providing any exploit, PoC, or patch details.

    00000396
    6.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5545 [ADVISORY] curl https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5545 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The message only references an advisory for CVE‑2026‑5545 with a hyperlink to details, offering no substantive technical or exploit information.

    0000033
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more