Intel

AIKIDO-2026-896244

libcurl is vulnerable to Information Disclosure

Information DisclosureCVE-2026-9546 Published 6 days ago

37

Low Risk

This Affects:

C++libcurl
8.18.0 - 8.20.0
Fixed in 8.21.0
Are you affected? Scan for Free

TL;DR

Setting CURLOPT_REFERER to NULL is documented to suppress the Referer header, but the previous value stays in the handle. Later requests on that handle still send the old Referer value, which discloses the prior URL to a server that should not receive it. The fix clears the stored referrer when the option is set to NULL.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you clear CURLOPT_REFERER on a reused easy handle.

Background info

libcurl is vulnerable to Information Disclosure in versions 8.18.0 - 8.20.0.

How to fix this

Upgrade the libcurl and/or the curl.curl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform