« Back to list

CVE-2026-5773

Status: ModifiedHigh (7.5)—

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers.

libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.

When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different "share" than the new subsequent transfer should.

This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

AV:N, PR:N, UI:N indica explotación remota sin privilegios (T1190). La reutilización incorrecta de conexión SMB permite leer archivos ajenos (C:H) o escribir en ubicaciones erróneas, afectando confidencialidad e integridad de datos.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-5773",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-5773",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-13T17:45:00.901945Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9",
      "affectedData": [
        {
          "vendor": "curl",
          "product": "curl",
          "versions": [
            {
              "status": "affected",
              "version": "7.40.0",
              "lessThan": "8.14.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "8.15.0",
              "lessThan": "8.16.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "8.17.0",
              "lessThan": "8.20.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://github.com/curl/curl.git",
          "vendor": "curl",
          "product": "curl",
          "versions": [
            {
              "status": "affected",
              "version": "aec2e865f06669b9cb5d26cc1148d70bc418b163",
              "lessThan": "74a169575d6412dc0ff532acdf94de35a6c2a571",
              "versionType": "git"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "curl",
          "product": "curl",
          "versions": [
            {
              "status": "affected",
              "version": "8.19.0"
            },
            {
              "status": "affected",
              "version": "8.18.0"
            },
            {
              "status": "affected",
              "version": "8.17.0"
            },
            {
              "status": "affected",
              "version": "8.16.0"
            },
            {
              "status": "affected",
              "version": "8.15.0"
            },
            {
              "status": "affected",
              "version": "8.14.1"
            },
            {
              "status": "affected",
              "version": "8.14.0"
            },
            {
              "status": "affected",
              "version": "8.13.0"
            },
            {
              "status": "affected",
              "version": "8.12.1"
            },
            {
              "status": "affected",
              "version": "8.12.0"
            },
            {
              "status": "affected",
              "version": "8.11.1"
            },
            {
              "status": "affected",
              "version": "8.11.0"
            },
            {
              "status": "affected",
              "version": "8.10.1"
            },
            {
              "status": "affected",
              "version": "8.10.0"
            },
            {
              "status": "affected",
              "version": "8.9.1"
            },
            {
              "status": "affected",
              "version": "8.9.0"
            },
            {
              "status": "affected",
              "version": "8.8.0"
            },
            {
              "status": "affected",
              "version": "8.7.1"
            },
            {
              "status": "affected",
              "version": "8.7.0"
            },
            {
              "status": "affected",
              "version": "8.6.0"
            },
            {
              "status": "affected",
              "version": "8.5.0"
            },
            {
              "status": "affected",
              "version": "8.4.0"
            },
            {
              "status": "affected",
              "version": "8.3.0"
            },
            {
              "status": "affected",
              "version": "8.2.1"
            },
            {
              "status": "affected",
              "version": "8.2.0"
            },
            {
              "status": "affected",
              "version": "8.1.2"
            },
            {
              "status": "affected",
              "version": "8.1.1"
            },
            {
              "status": "affected",
              "version": "8.1.0"
            },
            {
              "status": "affected",
              "version": "8.0.1"
            },
            {
              "status": "affected",
              "version": "8.0.0"
            },
            {
              "status": "affected",
              "version": "7.88.1"
            },
            {
              "status": "affected",
              "version": "7.88.0"
            },
            {
              "status": "affected",
              "version": "7.87.0"
            },
            {
              "status": "affected",
              "version": "7.86.0"
            },
            {
              "status": "affected",
              "version": "7.85.0"
            },
            {
              "status": "affected",
              "version": "7.84.0"
            },
            {
              "status": "affected",
              "version": "7.83.1"
            },
            {
              "status": "affected",
              "version": "7.83.0"
            },
            {
              "status": "affected",
              "version": "7.82.0"
            },
            {
              "status": "affected",
              "version": "7.81.0"
            },
            {
              "status": "affected",
              "version": "7.80.0"
            },
            {
              "status": "affected",
              "version": "7.79.1"
            },
            {
              "status": "affected",
              "version": "7.79.0"
            },
            {
              "status": "affected",
              "version": "7.78.0"
            },
            {
              "status": "affected",
              "version": "7.77.0"
            },
            {
              "status": "affected",
              "version": "7.76.1"
            },
            {
              "status": "affected",
              "version": "7.76.0"
            },
            {
              "status": "affected",
              "version": "7.75.0"
            },
            {
              "status": "affected",
              "version": "7.74.0"
            },
            {
              "status": "affected",
              "version": "7.73.0"
            },
            {
              "status": "affected",
              "version": "7.72.0"
            },
            {
              "status": "affected",
              "version": "7.71.1"
            },
            {
              "status": "affected",
              "version": "7.71.0"
            },
            {
              "status": "affected",
              "version": "7.70.0"
            },
            {
              "status": "affected",
              "version": "7.69.1"
            },
            {
              "status": "affected",
              "version": "7.69.0"
            },
            {
              "status": "affected",
              "version": "7.68.0"
            },
            {
              "status": "affected",
              "version": "7.67.0"
            },
            {
              "status": "affected",
              "version": "7.66.0"
            },
            {
              "status": "affected",
              "version": "7.65.3"
            },
            {
              "status": "affected",
              "version": "7.65.2"
            },
            {
              "status": "affected",
              "version": "7.65.1"
            },
            {
              "status": "affected",
              "version": "7.65.0"
            },
            {
              "status": "affected",
              "version": "7.64.1"
            },
            {
              "status": "affected",
              "version": "7.64.0"
            },
            {
              "status": "affected",
              "version": "7.63.0"
            },
            {
              "status": "affected",
              "version": "7.62.0"
            },
            {
              "status": "affected",
              "version": "7.61.1"
            },
            {
              "status": "affected",
              "version": "7.61.0"
            },
            {
              "status": "affected",
              "version": "7.60.0"
            },
            {
              "status": "affected",
              "version": "7.59.0"
            },
            {
              "status": "affected",
              "version": "7.58.0"
            },
            {
              "status": "affected",
              "version": "7.57.0"
            },
            {
              "status": "affected",
              "version": "7.56.1"
            },
            {
              "status": "affected",
              "version": "7.56.0"
            },
            {
              "status": "affected",
              "version": "7.55.1"
            },
            {
              "status": "affected",
              "version": "7.55.0"
            },
            {
              "status": "affected",
              "version": "7.54.1"
            },
            {
              "status": "affected",
              "version": "7.54.0"
            },
            {
              "status": "affected",
              "version": "7.53.1"
            },
            {
              "status": "affected",
              "version": "7.53.0"
            },
            {
              "status": "affected",
              "version": "7.52.1"
            },
            {
              "status": "affected",
              "version": "7.52.0"
            },
            {
              "status": "affected",
              "version": "7.51.0"
            },
            {
              "status": "affected",
              "version": "7.50.3"
            },
            {
              "status": "affected",
              "version": "7.50.2"
            },
            {
              "status": "affected",
              "version": "7.50.1"
            },
            {
              "status": "affected",
              "version": "7.50.0"
            },
            {
              "status": "affected",
              "version": "7.49.1"
            },
            {
              "status": "affected",
              "version": "7.49.0"
            },
            {
              "status": "affected",
              "version": "7.48.0"
            },
            {
              "status": "affected",
              "version": "7.47.1"
            },
            {
              "status": "affected",
              "version": "7.47.0"
            },
            {
              "status": "affected",
              "version": "7.46.0"
            },
            {
              "status": "affected",
              "version": "7.45.0"
            },
            {
              "status": "affected",
              "version": "7.44.0"
            },
            {
              "status": "affected",
              "version": "7.43.0"
            },
            {
              "status": "affected",
              "version": "7.42.1"
            },
            {
              "status": "affected",
              "version": "7.42.0"
            },
            {
              "status": "affected",
              "version": "7.41.0"
            },
            {
              "status": "affected",
              "version": "7.40.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-13T13:01:56.307",
  "references": [
    {
      "url": "https://curl.se/docs/CVE-2026-5773.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9"
    },
    {
      "url": "https://curl.se/docs/CVE-2026-5773.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9"
    },
    {
      "url": "https://hackerone.com/reports/3650689",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/04/29/9",
      "tags": [
        "Mailing List",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://hackerone.com/reports/3650689",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "2499f714-1537-4658-8207-48ae4bb9eae9",
      "description": [
        {
          "lang": "en",
          "value": "CWE-488"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same."
    }
  ],
  "lastModified": "2026-09-15T07:16:28.820",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ACA618E8-E657-401D-8884-FE82245671E2",
              "versionEndExcluding": "8.20.0",
              "versionStartIncluding": "7.40.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "2499f714-1537-4658-8207-48ae4bb9eae9"
}