A vulnerability in libcurl caused the HTTP Referer: header to persist even
when explicitly cleared. While the documentation states that passing NULL to
CURLOPT_REFERER suppresses the header, the option failed to clear the
internal state. As a result, the previous referrer string was erroneously
reused and sent in subsequent requests, potentially leaking sensitive
information to unintended servers.
{
"cna_assigner": "curl",
"cwe_ids": [
"CWE-200"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9546.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9546.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"329802710635362475633966257142929289229",
"59722172210655117825890418870938329781",
"183831522990858182837473479172905867047",
"304554302798540308152858876043779062238"
],
"threshold": 0.9
},
"id": "CVE-2026-9546-7ba9ca43",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/curl/curl.git/commit/862e8a74a84478d82973471b4f49dc2746c1780e",
"target": {
"file": "lib/transfer.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "192731219037552860576466850254657292841",
"length": 3790
},
"id": "CVE-2026-9546-93bc1aa3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/curl/curl.git/commit/862e8a74a84478d82973471b4f49dc2746c1780e",
"target": {
"file": "lib/transfer.c",
"function": "Curl_pretransfer"
}
}
]
"2026-10-08T07:15:45Z"