cbcvebase.
CVE-2026-9079
published 2026-07-03

CVE-2026-9079: libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for…

PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.58%
46.0th percentile
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl>= 8.15.0 < 8.16.18.16.1
curlcurl>= 8.17.0 < 8.20.18.20.1
curlcurl>= 8.8.0 < 8.14.28.14.2
curlcurl>= d5e83eb745762f48d8fafadc5df5dd3ae8d8941e < 88c7e16cceec816a2df45c899d49b1e85513f19388c7e16cceec816a2df45c899d49b1e85513f193
haxxcurl——
haxxcurl>= 8.8.0 < 8.21.08.21.0
rust-langrust——

Detection & IOCsextracted from sources · hover to see the quote

  • →Monitor for unexpected reuse of proxy authentication credentials across libcurl-based transfers — a single handle or session reusing proxy credentials after an explicit clear (e.g., setting CURLOPT_PROXYUSERPWD to empty/NULL) is indicative of the vulnerable behaviour. ↗
  • →Affected binaries/libraries to target in asset inventory and runtime scanning: libcurl-1.dll (Windows), libcurl.so (Linux), and applications shipping bundled libcurl such as curl, rust toolchain packages, and davix. ↗
  • ·dotnet8.0 on Red Hat Enterprise Linux 8 is confirmed NOT affected; avoid false-positive alerting on this package. ↗
  • ·No integrity or availability impact — the risk is limited to information disclosure (proxy credentials leaking to subsequent transfers). Prioritise accordingly in risk scoring. ↗
  • ·No vendor-provided mitigation meets Red Hat's deployment/stability criteria; patching the affected libcurl package is the only remediation path. ↗
  • ·Community-tracked packages (e.g., davix in EPEL) require individual maintainer assessment before confirming impact; do not assume all EPEL packages bundling libcurl are affected without verification. ↗

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.