Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-5773
curl curl — wrong reuse of SMB connection
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H N N 7.5 .0066 49.7 —
AFFECTED
Product Versions Fixed
curl 7.40.0 – —
curl aec2e865f06669b9cb5d26cc1148d70bc418b163 – —
curl 8.19.0 – —
TIMELINE
Apr 8 Reserved by curl
May 13 Published (CNA: curl)
Sep 15 EXPLOIT PUBLISHED — CVE-2026-5773 (curl). Public exploit reference added.
Description
libcurl might in some circumstances reuse the wrong connection for SMB(S)
transfers.
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a network transfer operation that was requested by an
application could wrongfully reuse an existing SMB connection to the same
server that was using a different "share" than the new subsequent transfer
should.
This could in unlucky situations lead to the download of the wrong file or the
upload of a file to the wrong place. When this happens, the same credentials
are used and the server name is the same.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| April 8, 2026 | Reserved | Reserved by curl |
| May 13, 2026 | Published | Published (CNA: curl) |
| September 15, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-5773 (curl). Public exploit reference added. |
Affected
Affected products and packages — 3 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| curl | curl | — | 7.40.0 | — |
| curl | curl | — | aec2e865f06669b9cb5d26cc1148d70bc418b163 | — |
| curl | curl | — | 8.19.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-5773 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.