curl might erroneously pass on credentials for a first proxy to a second
proxy.
This can happen when the following conditions are true:
1. curl is setup to use specific different proxies for different URL schemes
2. the first proxy needs credentials
3. the second proxy uses no credentials
4. while using the first proxy (using say `http://`), curl is asked to follow
a redirect to a URL using another scheme (say `https://`), accessed using a
second, different, proxy
References
| Link | Resource |
|---|---|
| https://curl.se/docs/CVE-2026-6253.html | Patch Vendor Advisory |
| https://curl.se/docs/CVE-2026-6253.json | Vendor Advisory |
| https://hackerone.com/reports/3669637 | Exploit Issue Tracking Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/04/29/11 | Mailing List Patch Third Party Advisory |
| https://hackerone.com/reports/3669637 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
14 May 2026, 13:40
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-522 | |
| References | () https://curl.se/docs/CVE-2026-6253.html - Patch, Vendor Advisory | |
| References | () https://curl.se/docs/CVE-2026-6253.json - Vendor Advisory | |
| References | () https://hackerone.com/reports/3669637 - Exploit, Issue Tracking, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/04/29/11 - Mailing List, Patch, Third Party Advisory | |
| CPE | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | |
| First Time |
Haxx
Haxx curl |
13 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.9 |
| References | () https://hackerone.com/reports/3669637 - |
13 May 2026, 14:50
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-13 13:01
Updated : 2026-05-14 13:40
NVD link : CVE-2026-6253
Mitre link : CVE-2026-6253
CVE.ORG link : CVE-2026-6253
JSON object : View
Products Affected
haxx
- curl
CWE
CWE-522
Insufficiently Protected Credentials
