CVE-2026-9545: exposing HTTP/3 early data

Published Jul 3, 2026
·
Updated

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.

When libcurl returns to the hostname the second time with a cached SSL session (CURLOPTSSLSESSIONIDCACHE is not disabled) and early data enabled (the CURLSSLOPTEARLYDATA bit is set in CURLOPTSSLOPTIONS), libcurl might send off the second request's bytes on that new connection before enforcing the certificate verification failure. Potentially leaking sensitive information.

Affected Software

2 affected componentsFixes available
debian/curl<=8.14.1-2+deb13u3, <=8.20.0-5
7.74.0-1.3+deb11u137.74.0-1.3+deb11u167.88.1-10+deb12u147.88.1-10+deb12u58.21.0-2
haxx curl>=8.11.0<8.21.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/curl to a version that resolves this vulnerability.

    Fixed in 7.74.0-1.3+deb11u13Fixed in 7.74.0-1.3+deb11u16Fixed in 7.88.1-10+deb12u14Fixed in 7.88.1-10+deb12u5Fixed in 8.21.0-2
  2. Configuration

    Disable HTTP/3 early data by ensuring the CURLSSLOPT_EARLYDATA bit is not set in CURLOPT_SSL_OPTIONS, since early data may be sent on an impostor connection before certificate verification failure.

    libcurl CURLOPT_SSL_OPTIONS (CURLSSLOPT_EARLYDATA bit) = unset/disabled
  3. Compensating control

    Disable or avoid using a cached SSL session for the target hostname (CURLOPT_SSL_SESSIONID_CACHE is not disabled in the described scenario), so libcurl does not reuse a cached SSL session that could lead to sensitive information being sent on a replacement connection before verification failure.

Event History

Jul 1, 2026
Data Sourced
via Debian·03:07 AM
DescriptionAffected Software
Jul 3, 2026
Data Sourced
via Ubuntu·03:08 AM
RemedyDescriptionSeverityAffected Software
CVE Published
via MITRE·06:17 AM
Data Sourced
via MITRE·06:17 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
RemedyDescriptionSeverityAffected Software
Apr 11, 58531
Event
via FIRST·04:50 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9545?

CVE-2026-9545 has a risk score of 21, indicating a high level of concern due to potential exposure of sensitive data.

2

How do I fix CVE-2026-9545?

To fix CVE-2026-9545, update to the latest version of libcurl that addresses this vulnerability.

3

What are the potential impacts of CVE-2026-9545?

CVE-2026-9545 could allow an attacker to intercept and manipulate sensitive data due to HTTP/3 early data exposure.

4

Who is affected by CVE-2026-9545?

Users and systems utilizing the affected versions of libcurl for HTTP/3 communications are at risk from CVE-2026-9545.

5

What versions of libcurl are vulnerable to CVE-2026-9545?

CVE-2026-9545 affects earlier versions of libcurl that do not implement the necessary safeguards for HTTP/3 early data transfers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203