cbcvebase.
CVE-2026-9079
published 2026-07-03

CVE-2026-9079: libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for…

PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.58%
44.6th percentile
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

Affected

22 ranges
VendorProductVersion rangeFixed in
curlcurl8.10.0 – 8.10.0
curlcurl8.10.1 – 8.10.1
curlcurl8.11.0 – 8.11.0
curlcurl8.11.1 – 8.11.1
curlcurl8.12.0 – 8.12.0
curlcurl8.12.1 – 8.12.1
curlcurl8.13.0 – 8.13.0
curlcurl8.14.0 – 8.14.0
curlcurl8.14.1 – 8.14.1
curlcurl8.15.0 – 8.15.0
curlcurl8.16.0 – 8.16.0
curlcurl8.17.0 – 8.17.0
curlcurl8.18.0 – 8.18.0
curlcurl8.19.0 – 8.19.0
curlcurl8.20.0 – 8.20.0
curlcurl8.8.0 – 8.8.0
curlcurl8.9.0 – 8.9.0
curlcurl8.9.1 – 8.9.1
haxxcurl
haxxcurl>= 8.8.0 < 8.21.08.21.0
rust-langrust
ubuntucurl

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for unexpected reuse of proxy authentication credentials across libcurl-based transfers — a single handle or session reusing proxy credentials after an explicit clear (e.g., setting CURLOPT_PROXYUSERPWD to empty/NULL) is indicative of the vulnerable behaviour.
  • Affected binaries/libraries to target in asset inventory and runtime scanning: libcurl-1.dll (Windows), libcurl.so (Linux), and applications shipping bundled libcurl such as curl, rust toolchain packages, and davix.
  • ·dotnet8.0 on Red Hat Enterprise Linux 8 is confirmed NOT affected; avoid false-positive alerting on this package.
  • ·No integrity or availability impact — the risk is limited to information disclosure (proxy credentials leaking to subsequent transfers). Prioritise accordingly in risk scoring.
  • ·No vendor-provided mitigation meets Red Hat's deployment/stability criteria; patching the affected libcurl package is the only remediation path.
  • ·Community-tracked packages (e.g., davix in EPEL) require individual maintainer assessment before confirming impact; do not assume all EPEL packages bundling libcurl are affected without verification.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.