← Back

CVE-2026-9079

nvd nist
Published: Jul 3, 2026Modified: Jul 7, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

Affected (1)

Products: Haxx: Curl
1 product
Curl
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 8.8.0 to 8.21.0

References (4)

Source: 2499f714-1537-4658-8207-48ae4bb9eae9
PatchVendor Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Vendor Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
ExploitIssue TrackingThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitIssue TrackingThird Party Advisory

Timeline

No history available yet.