libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers.
libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different "share" than the new subsequent transfer should.
This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.
{
"cna_assigner": "curl",
"cwe_ids": [
"CWE-488"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5773.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "7.40.0"
},
{
"fixed": "8.14.2"
},
{
"introduced": "8.15.0"
},
{
"fixed": "8.16.1"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-5773.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"283484103587021140185473640195385188213",
"51413613464287816571195646581916328705",
"50657125667698113139735675550160507197",
"109745977035312476342802684866473502970",
"155876444996527445678040642288005699706",
"189120337197838981146493639364407128017",
"110638884583177156814419953150639226214",
"58536000395487246013630143241898699709"
],
"threshold": 0.9
},
"id": "CVE-2026-5773-ce96841d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/curl/curl.git/commit/74a169575d6412dc0ff532acdf94de35a6c2a571",
"target": {
"file": "lib/protocol.c"
}
}
]
"2026-09-30T08:14:05Z"