libcurl : Referer Header Persists After NULL Clearing (CVE-2026-9546)
CVE-2026-9546 Published on July 3, 2026
sending old referer
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even
when explicitly cleared. While the documentation states that passing NULL to
`CURLOPT_REFERER` suppresses the header, the option failed to clear the
internal state. As a result, the previous referrer string was erroneously
reused and sent in subsequent requests, potentially leaking sensitive
information to unintended servers.
Vulnerability Analysis
CVE-2026-9546 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. An automatable proof of concept (POC) exploit exists. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-9546 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-9546
Want to know whenever a new CVE is published for Haxx Curl? stack.watch will email you.
Affected Versions
curl:- Version 8.18.0 and below 8.20.1 is affected.
- Version 2cb868242dc2ac9cd52ee64987ef51d5964a56f9 and below 862e8a74a84478d82973471b4f49dc2746c1780e is affected.
- Version 8.20.0 is affected.
- Version 8.19.0 is affected.
- Version 8.18.0 is affected.