| Type | URI |
|---|---|
| Patch | https://curl.se/docs/CVE-2026-7009.html |
| Product | https://curl.se/docs/CVE-2026-7009.json |
| Exploit | https://hackerone.com/reports/3694390 |
| Mailing List | http://www.openwall.com/lists/oss-security/2026/04/29/12 |
| CPE URI | Source package | Min version | Max version |
|---|---|---|---|
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* |
curl | >= 8.17.0 | < 8.20.0 |
| Source package | Branch | Version | Maintainer | Status |
|---|---|---|---|---|
| curl | edge-main | 8.20.0-r0 | Achill Gilgenast <achill@achill.org> | fixed |
| curl | edge-main | 8.19.0-r0 | Achill Gilgenast <achill@achill.org> | possibly vulnerable |
| curl | edge-main | 8.18.0-r0 | Achill Gilgenast <achill@achill.org> | possibly vulnerable |
| curl | edge-main | 8.17.0-r1 | Achill Gilgenast <achill@achill.org> | possibly vulnerable |
| curl | edge-main | 8.17.0-r0 | Achill Gilgenast <achill@achill.org> | possibly vulnerable |
| curl | 3.23-main | 8.19.0-r0 | Achill Gilgenast <achill@achill.org> | possibly vulnerable |
| curl | 3.23-main | 8.17.0-r1 | Achill Gilgenast <achill@achill.org> | possibly vulnerable |