A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.
{
"cna_assigner": "curl",
"cwe_ids": [
"CWE-319"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4873.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "7.20.0"
},
{
"fixed": "8.14.2"
},
{
"introduced": "8.15.0"
},
{
"fixed": "8.16.1"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-4873.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "169885633457962860362958220457320236532",
"length": 399
},
"id": "CVE-2026-4873-432df36b",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/curl/curl.git/commit/507e7be573b0a76fca597b75ff7cb27a66e7d865",
"target": {
"file": "lib/url.c",
"function": "url_match_ssl_use"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"186702639195371621663220614719413669739",
"98146386134768362884346766368977077720",
"144008511706963310545008089099783743644",
"214623997824184722186061516736204732779",
"124575361568450278741812246576167336919",
"105135349804760838859480469610730392589",
"193100289411074928523858916880171338604",
"6936524333846488920218514747282650233",
"276618269211397366230394600852763568259",
"229942947754903715914943302740058426565",
"288248169414681199400959167724664616055"
],
"threshold": 0.9
},
"id": "CVE-2026-4873-731b3328",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/curl/curl.git/commit/507e7be573b0a76fca597b75ff7cb27a66e7d865",
"target": {
"file": "lib/url.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "141979231375931355570407370477556625049",
"length": 1203
},
"id": "CVE-2026-4873-9a7ca877",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/curl/curl.git/commit/507e7be573b0a76fca597b75ff7cb27a66e7d865",
"target": {
"file": "lib/url.c",
"function": "url_attach_existing"
}
}
]
"2026-09-30T08:09:03Z"