Description
A flaw was found in curl. A remote attacker could exploit this by initiating an unencrypted connection (via IMAP, SMTP, or POP3) and then making a subsequent request to the same host that requires Transport Layer Security (TLS). Due to incorrect connection reuse, the subsequent request would bypass the TLS requirement, leading to the transmission of sensitive information in cleartext. This vulnerability, categorized as Cleartext Transmission of Sensitive Information (CWE-319), results in information disclosure.
INFO
Published Date :
Last Modified :
Source :
AFFECTED PRODUCTS
The following products are affected by CVE-2026-4873 vulnerability.
| Vendors | Products |
|---|---|
| Curl |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-4873.