A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.
{
"cna_assigner": "curl",
"cwe_ids": [
"CWE-319"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4873.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "7.20.0"
},
{
"fixed": "8.14.2"
},
{
"introduced": "8.15.0"
},
{
"fixed": "8.16.1"
},
{
"introduced": "ec3bb8f727405642a471b4b1b9eb0118fc003104"
},
{
"fixed": "507e7be573b0a76fca597b75ff7cb27a66e7d865"
}
],
"source": "AFFECTED_FIELD"
}
]
}