Skip to content
VulniPulse
High7.5NetApp

High [CVE-2026-3805] Libcurl Vulnerability in NetApp Products

This high-severity NetApp advisory covers CVE-2026-3805 affecting ONTAP 9, ONTAP tools for VMware vSphere 10.

NTAP-20260327-0001 Published Mar 27, 2026Updated by vendor Jul 22, 2026
Affected products & platforms
NetAppONTAP tools for VMware
Open vendor advisory

Android app · Google Play

Monitor future NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Multiple NetApp products incorporate Libcurl. Libcurl versions 8.13.0 prior to 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: ONTAP 9, ONTAP tools for VMware vSphere 10.

NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

Affected versions
  • 8.13.0
  • 8.19.0

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Fixed versions
  • ONTAP 9: 9.13.1P21
  • ONTAP 9: 9.16.1P14
  • ONTAP 9: 9.17.1P9
  • ONTAP 9: 9.18.1P4
  • ONTAP 9: 9.19.1
  • ONTAP tools for VMware vSphere 10: 10.5P2

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Update affected NetApp products to a fixed release: ONTAP 9: 9.13.1P21, ONTAP 9: 9.16.1P14, ONTAP 9: 9.17.1P9, ONTAP 9: 9.18.1P4, ONTAP 9: 9.19.1, ONTAP tools for VMware vSphere 10: 10.5P2.

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.