CVE-2026-4873

Published: Mag 13, 2026 Last Modified: Mag 13, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

A vulnerability exists where a connection requiring TLS incorrectly reuses an
existing unencrypted connection from the same connection pool. If an initial
transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request
to that same host bypasses the TLS requirement and instead transmit data
unencrypted.

https://curl.se/docs/CVE-2026-4873.html
https://curl.se/docs/CVE-2026-4873.json
https://hackerone.com/reports/3621851
http://www.openwall.com/lists/oss-security/2026/04/29/7