https://seclists.org/oss-sec/2026/q2/265: [ADVISORY] curl: CVE-2026-4873: connection use ignos TLS quiment
Published Apr 29, 2026
·Updated
Affected Software
2 affected components
curl libcurl>=7.20.0<=8.19.0
curl curl>=7.20.0<=8.19.0
Frequently Asked Questions
1
What is the severity of CVE-2026-4873?
CVE-2026-4873 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2026-4873?
To fix CVE-2026-4873, update your curl or libcurl to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2026-4873?
CVE-2026-4873 affects all versions of curl and libcurl that allow connection reuse without proper TLS enforcement.
4
What kind of attack can exploit CVE-2026-4873?
CVE-2026-4873 can potentially allow an attacker to intercept or manipulate data due to improper TLS enforcement on reused connections.
5
Is CVE-2026-4873 a denial of service vulnerability?
CVE-2026-4873 is not classified as a denial of service vulnerability; it primarily affects connection security integrity.