CVE-2026-11352

curl vulnerabilities

Beschreibung

Ein Problem in der QUIC-UDP-Empfangsfunktion von curl ermöglicht es einem böswilligen HTTP/3-Server, einen Fern-Denial-of-Service gegen einen curl oder libcurl-Klienten auszulösen. Da die Hilfsfunktion Null-Längen-UDP-Datagramme vor dem Zählen für das pro-Aufruf-Paketbudget verwirft, kann ein verbundener QUIC-Peer kontinuierlich leere Datagramme an den Klienten senden, um diesen unbegrenzt zu blockieren.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.5
Quelle: nvd-v3
51.6 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.7 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-09 19:14 UTC

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-07-06 19:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    • Reference: https://hackerone.com/reports/3783438
    • SSVC: {"id":"CVE-2026-11352","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalI…
  2. New CVE Received2026-07-03 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
    • Affected: curl
    • Description: An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.
    • Reference: https://curl.se/docs/CVE-2026-11352.html
    • Reference: https://curl.se/docs/CVE-2026-11352.json

Betroffene Betriebssysteme

  • linux

    ubuntu / curlbionic

  • linux

    ubuntu / curlfocal

  • linux

    ubuntu / curlnoble

  • linux

    ubuntu / curlquesting

  • linux

    ubuntu / curlresolute

  • linux

    ubuntu / curltrusty

  • linux

    ubuntu / curlxenial

  • linux

    debian / debian_linux11.0

  • other

    netapp / bootstrap_os

  • other

    netapp / h300s_firmware

  • other

    netapp / h410s_firmware

  • other

    netapp / h500s_firmware

  • other

    netapp / h610c_firmware

  • other

    netapp / h610s_firmware

  • other

    netapp / h615c_firmware

  • other

    netapp / h700s_firmware

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Splunk

    Splunk Enterprise< 10.0.9

    gefixt in 10.0.9

  • Splunk

    Splunk Enterprise< 10.2.6

    gefixt in 10.2.6

  • Splunk

    Splunk Enterprise< 10.4.2

    gefixt in 10.4.2

  • Splunk

    Splunk Enterprise< 9.4.14

    gefixt in 9.4.14

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-11352