CVE-2026-9079
published 2026-07-03CVE-2026-9079: libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for…
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.58%
44.6th percentile
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 8.10.0 – 8.10.0 | — |
| curl | curl | 8.10.1 – 8.10.1 | — |
| curl | curl | 8.11.0 – 8.11.0 | — |
| curl | curl | 8.11.1 – 8.11.1 | — |
| curl | curl | 8.12.0 – 8.12.0 | — |
| curl | curl | 8.12.1 – 8.12.1 | — |
| curl | curl | 8.13.0 – 8.13.0 | — |
| curl | curl | 8.14.0 – 8.14.0 | — |
| curl | curl | 8.14.1 – 8.14.1 | — |
| curl | curl | 8.15.0 – 8.15.0 | — |
| curl | curl | 8.16.0 – 8.16.0 | — |
| curl | curl | 8.17.0 – 8.17.0 | — |
| curl | curl | 8.18.0 – 8.18.0 | — |
| curl | curl | 8.19.0 – 8.19.0 | — |
| curl | curl | 8.20.0 – 8.20.0 | — |
| curl | curl | 8.8.0 – 8.8.0 | — |
| curl | curl | 8.9.0 – 8.9.0 | — |
| curl | curl | 8.9.1 – 8.9.1 | — |
| haxx | curl | — | — |
| haxx | curl | >= 8.8.0 < 8.21.0 | 8.21.0 |
| rust-lang | rust | — | — |
| ubuntu | curl | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unexpected reuse of proxy authentication credentials across libcurl-based transfers — a single handle or session reusing proxy credentials after an explicit clear (e.g., setting CURLOPT_PROXYUSERPWD to empty/NULL) is indicative of the vulnerable behaviour. ↗
- →Affected binaries/libraries to target in asset inventory and runtime scanning: libcurl-1.dll (Windows), libcurl.so (Linux), and applications shipping bundled libcurl such as curl, rust toolchain packages, and davix. ↗
- ·dotnet8.0 on Red Hat Enterprise Linux 8 is confirmed NOT affected; avoid false-positive alerting on this package. ↗
- ·No integrity or availability impact — the risk is limited to information disclosure (proxy credentials leaking to subsequent transfers). Prioritise accordingly in risk scoring. ↗
- ·No vendor-provided mitigation meets Red Hat's deployment/stability criteria; patching the affected libcurl package is the only remediation path. ↗
- ·Community-tracked packages (e.g., davix in EPEL) require individual maintainer assessment before confirming impact; do not assume all EPEL packages bundling libcurl are affected without verification. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
curl libcURL up to 8.20.0 insufficiently protected credentials (EUVD-2026-41510)
vuldb·2026-07-03
CVE-2026-9079 [LOW] curl libcURL up to 8.20.0 insufficiently protected credentials (EUVD-2026-41510)
A vulnerability was found in curl libcURL. It has been declared as problematic. The affected element is an unknown function. The manipulation results in insufficiently protected credentials.
This vulnerability is cataloged as CVE-2026-9079. The attack may be launched remotely. There is no exploit available.
GHSA
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know
ghsa_unreviewed·2026-07-03
CVE-2026-9079 libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Red Hat
libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
vendor_redhat·2026-07-03·CVSS 9.8
CVE-2026-9079 [CRITICAL] CWE-212 libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
A flaw was found in curl. When libcurl is instructed to clear proxy authentication credentials, it fails to do so, leaving the old credentials available. This could lead to the unintended reuse of sensitive proxy authentication credentials for subsequent network transfers, potentially resulting in unauthorized access or information disclosure.
Statement: Important: A flaw in libcurl's proxy authentication credential management can lead to information disclosure. There are no integ
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-06-30
CVE-2026-8286 curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Andrew Nesbitt discovered that curl could reuse an existing live
connection during STARTTLS-based connection upgrades even when the TLS
configuration did not match. A remote attacker could possibly use this
issue to cause curl to use an unintended TLS configuration.
(CVE-2026-8286)
Muhamad Arga Reksapati discovered that curl incorrectly reused
connections for Negotiate-authenticated requests when different services
were involved. A remote attacker could possibly use this issue to access
resources authenticated for another service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458)
It was discovered that curl i
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-9079 davix: libcurl: Information disclosure due to failure to clear proxy authentication credentials [epel-all]
bugzilla·2026-07-06·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 davix: libcurl: Information disclosure due to failure to clear proxy authentication credentials [epel-all]
CVE-2026-9079 davix: libcurl: Information disclosure due to failure to clear proxy authentication credentials [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Bugzilla
CVE-2026-9079 libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
bugzilla·2026-07-03·CVSS 9.8
CVE-2026-9079 [CRITICAL] CVE-2026-9079 libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
CVE-2026-9079 libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
2026-07-03
Published