libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
References
| Link | Resource |
|---|---|
| https://curl.se/docs/CVE-2026-9079.html | Patch Vendor Advisory |
| https://curl.se/docs/CVE-2026-9079.json | Vendor Advisory |
| https://hackerone.com/reports/3750295 | Exploit Issue Tracking Third Party Advisory |
| https://hackerone.com/reports/3750295 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
07 Jul 2026, 15:05
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-522 | |
| References | () https://curl.se/docs/CVE-2026-9079.html - Patch, Vendor Advisory | |
| References | () https://curl.se/docs/CVE-2026-9079.json - Vendor Advisory | |
| References | () https://hackerone.com/reports/3750295 - Exploit, Issue Tracking, Third Party Advisory | |
| First Time |
Haxx curl
Haxx |
|
| CPE | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* |
06 Jul 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://hackerone.com/reports/3750295 - | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
03 Jul 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-03 07:16
Updated : 2026-07-07 15:05
NVD link : CVE-2026-9079
Mitre link : CVE-2026-9079
CVE.ORG link : CVE-2026-9079
JSON object : View
Products Affected
haxx
- curl
CWE
CWE-522
Insufficiently Protected Credentials
