Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-11352

Опубликовано: 03 июл. 2026
Источник: debian

Описание

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed8.21.0~rc2-1package
curlnot-affectedtrixiepackage
curlnot-affectedbookwormpackage
curlnot-affectedbullseyepackage

Примечания

  • https://curl.se/docs/CVE-2026-11352.html

  • Introduced with: https://github.com/curl/curl/commit/6a3d0b6d631d5e9bec797306b5b41a9f440a088d (curl-8_18_0)

  • Fixed by: https://github.com/curl/curl/commit/56eca2afb4806f1032872fa97d1834b3c1385276 (rc-8_21_0-2, curl-8_21_0)

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

CVSS3: 7.5
redhat
около 1 месяца назад

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

CVSS3: 7.5
nvd
около 1 месяца назад

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

CVSS3: 7.5
github
около 1 месяца назад

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

CVSS3: 6.5
fstec
2 месяца назад

Уязвимости функции приема UDP-пакетов QUIC библиотеки libcurl программного средства для взаимодействия с серверами cURL, позволяющая нарушителю вызвать отказ в обслуживании