Is the DLP vulnerable to CVE-2026-9545
search cancel

Is the DLP vulnerable to CVE-2026-9545

book

Article ID: 450679

calendar_today

Updated On:

Products

Data Loss Prevention Core Package

Issue/Introduction

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libcurl returns to the hostname the second time with a cached SSL session (CURLOPT_SSL_SESSIONID_CACHE is not disabled) and early data enabled (the CURLSSLOPT_EARLYDATA bit is set in CURLOPT_SSL_OPTIONS), libcurl might send off the second request's bytes on that new connection before enforcing the certificate verification failure. Potentially leaking sensitive information.

Resolution

This vulnerability requires both CURLSSLOPT_EARLYDATA and HTTP/3 functionality. DLP does not enable TLS early-data in its SSL configuration under any circumstances, nor does it utilize the HTTP/3 functionality of CURL. Because the necessary exploit conditions are not met, the final verdict is NOT_EXPLOITABLE.