CVE-2026-9079
published 2026-07-03CVE-2026-9079: libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for…
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.58%
46.0th percentile
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | >= 8.15.0 < 8.16.1 | 8.16.1 |
| curl | curl | >= 8.17.0 < 8.20.1 | 8.20.1 |
| curl | curl | >= 8.8.0 < 8.14.2 | 8.14.2 |
| curl | curl | >= d5e83eb745762f48d8fafadc5df5dd3ae8d8941e < 88c7e16cceec816a2df45c899d49b1e85513f193 | 88c7e16cceec816a2df45c899d49b1e85513f193 |
| haxx | curl | — | — |
| haxx | curl | >= 8.8.0 < 8.21.0 | 8.21.0 |
| rust-lang | rust | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unexpected reuse of proxy authentication credentials across libcurl-based transfers — a single handle or session reusing proxy credentials after an explicit clear (e.g., setting CURLOPT_PROXYUSERPWD to empty/NULL) is indicative of the vulnerable behaviour. ↗
- →Affected binaries/libraries to target in asset inventory and runtime scanning: libcurl-1.dll (Windows), libcurl.so (Linux), and applications shipping bundled libcurl such as curl, rust toolchain packages, and davix. ↗
- ·dotnet8.0 on Red Hat Enterprise Linux 8 is confirmed NOT affected; avoid false-positive alerting on this package. ↗
- ·No integrity or availability impact — the risk is limited to information disclosure (proxy credentials leaking to subsequent transfers). Prioritise accordingly in risk scoring. ↗
- ·No vendor-provided mitigation meets Red Hat's deployment/stability criteria; patching the affected libcurl package is the only remediation path. ↗
- ·Community-tracked packages (e.g., davix in EPEL) require individual maintainer assessment before confirming impact; do not assume all EPEL packages bundling libcurl are affected without verification. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
curl libcURL up to 8.20.0 insufficiently protected credentials (EUVD-2026-41510)
vuldb·2026-07-03
CVE-2026-9079 [LOW] curl libcURL up to 8.20.0 insufficiently protected credentials (EUVD-2026-41510)
A vulnerability was found in curl libcURL. It has been declared as problematic. The affected element is an unknown function. The manipulation results in insufficiently protected credentials.
This vulnerability is cataloged as CVE-2026-9079. The attack may be launched remotely. There is no exploit available.
GHSA
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know
ghsa_unreviewed·2026-07-03
CVE-2026-9079 libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Ubuntu
curl regression
vendor_ubuntu·2026-09-28·CVSS 8.1
CVE-2026-8286 [HIGH] curl regression
Title: curl regression
Summary: USN-8487-1 introduced a regression in curl.
USN-8487-1 fixed vulnerabilities in curl. Unfortunately that update
contained an incomplete fix for CVE-2026-8927. This update fixes the
problem.
Original advisory details:
Andrew Nesbitt discovered that curl could reuse an existing live
connection during STARTTLS-based connection upgrades even when the TLS
configuration did not match. A remote attacker could possibly use this
issue to cause curl to use an unintended TLS configuration.
(CVE-2026-8286)
Muhamad Arga Reksapati discovered that curl incorrectly reused connections
for Negotiate-authenticated requests when different services were
involved. A remote attacker could possibly use this issue to access
resources authenticated for another service. This issu
Red Hat
libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
vendor_redhat·2026-07-03·CVSS 9.8
CVE-2026-9079 [CRITICAL] CWE-212 libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
A flaw was found in curl. When libcurl is instructed to clear proxy authentication credentials, it fails to do so, leaving the old credentials available. This could lead to the unintended reuse of sensitive proxy authentication credentials for subsequent network transfers, potentially resulting in unauthorized access or information disclosure.
Statement: Important: A flaw in libcurl's proxy authentication credential management can lead to information disclosure. There are no integ
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-06-30
CVE-2026-8286 curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Andrew Nesbitt discovered that curl could reuse an existing live
connection during STARTTLS-based connection upgrades even when the TLS
configuration did not match. A remote attacker could possibly use this
issue to cause curl to use an unintended TLS configuration.
(CVE-2026-8286)
Muhamad Arga Reksapati discovered that curl incorrectly reused
connections for Negotiate-authenticated requests when different services
were involved. A remote attacker could possibly use this issue to access
resources authenticated for another service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458)
It was discovered that curl i
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-9079 mingw-curl: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
bugzilla·2026-08-31·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 mingw-curl: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
CVE-2026-9079 mingw-curl: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Bugzilla
CVE-2026-9079 rust: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
bugzilla·2026-08-31·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 rust: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
CVE-2026-9079 rust: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Discussion:
rust uses the system (fedora's) libcurl. The fix is within libcurl. There is nothing to fix in rust.
Bugzilla
CVE-2026-9079 trustee-guest-components: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
bugzilla·2026-08-31·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 trustee-guest-components: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
CVE-2026-9079 trustee-guest-components: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Bugzilla
CVE-2026-9079 nushell: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
bugzilla·2026-08-31·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 nushell: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
CVE-2026-9079 nushell: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Bugzilla
CVE-2026-9079 stgit: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
bugzilla·2026-08-31·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 stgit: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
CVE-2026-9079 stgit: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Discussion:
stgit dynamically links libcurl. This issue can't be fixed in stgit, it must be fixed in libcurl directly.
Bugzilla
CVE-2026-9079 nushell: libcurl: Information disclosure due to failure to clear proxy authentication credentials [epel-all]
bugzilla·2026-08-31·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 nushell: libcurl: Information disclosure due to failure to clear proxy authentication credentials [epel-all]
CVE-2026-9079 nushell: libcurl: Information disclosure due to failure to clear proxy authentication credentials [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Bugzilla
CVE-2026-9079 rpi-imager: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
bugzilla·2026-08-31·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 rpi-imager: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
CVE-2026-9079 rpi-imager: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Bugzilla
CVE-2026-9079 rustup: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
bugzilla·2026-08-31·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 rustup: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
CVE-2026-9079 rustup: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Bugzilla
CVE-2026-9079 curl: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
bugzilla·2026-07-31·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 curl: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
CVE-2026-9079 curl: libcurl: Information disclosure due to failure to clear proxy authentication credentials [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Bugzilla
CVE-2026-9079 davix: libcurl: Information disclosure due to failure to clear proxy authentication credentials [epel-all]
bugzilla·2026-07-06·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 davix: libcurl: Information disclosure due to failure to clear proxy authentication credentials [epel-all]
CVE-2026-9079 davix: libcurl: Information disclosure due to failure to clear proxy authentication credentials [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Bugzilla
CVE-2026-9079 libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
bugzilla·2026-07-03·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
CVE-2026-9079 libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
2026-07-03
Published