Logo
vulnerabilityCVE-2026-5773
Name
CVE-2026-5773
Source
NVD ( link)Debian ( link)
Description
libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different 'share' than the new subsequent transfer should. This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.
Published Date
Updated Date
Workaround
-

Analysis#


Vulnerability Ratings#


7.5
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
8.20.0
Not Affected
buildroot
master
8.21.0
Not Affected
openwrt
master
8.19.0-r2
Exploitable
openwrt
master
8.20.0-r1
Not Affected
yocto
kirkstone
7.82.0
Exploitable
yocto
master
8.20.0
Not Affected
yocto
scarthgap
8.7.1
Exploitable