Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-8927: curl may send proxy credentials to wrong server

CVE-2026-8927 · published 3 months ago
Summary

The curl tool can accidentally attach authentication information meant for one proxy to a request that goes through a different proxy. This could let the second proxy see credentials that were intended only for the first proxy. Update curl to the latest version to stop the credential leakage.

What to do
  • Update canonical curl to version 7.35.0-1ubuntu2.20+esm20.
  • Update canonical curl to version 7.47.0-1ubuntu2.19+esm16.
  • Update canonical curl to version 7.58.0-2ubuntu3.24+esm9.
  • Update canonical curl to version 7.68.0-1ubuntu2.25+esm4.
  • Update canonical curl to version 7.81.0-1ubuntu1.25.
  • Update canonical curl to version 8.5.0-2ubuntu10.10.
  • Update canonical curl to version 8.14.1-2ubuntu1.4.
  • Update canonical curl to version 8.18.0-1ubuntu2.2.
  • Update bellsoft curl to version 8.21.0-r0.
  • Update debian curl to version 8.21.0~rc2-1.
  • Update debian rootio-curl to version 7.88.1-10+deb12u15.aikido.13.
  • Update alpine curl to version 8.19.0-r00074.
  • Update alpine rootio-curl to version 8.19.0-r00074.
  • Update alpine curl to version 8.14.1-r20071.
  • Update alpine rootio-curl to version 8.14.1-r20071.
  • Update alpine curl to version 8.14.1-r20072.
  • Update alpine curl to version 8.14.1-r20074.
  • Update alpine rootio-curl to version 8.14.1-r20074.
  • Update alpine rootio-curl to version 8.14.1-r20077.
  • Update alpine curl to version 8.14.1-r20078.
  • Update alpine rootio-curl to version 8.14.1-r20078.
  • Update alpine curl to version 8.14.1-r20077.
  • Update alpine rootio-curl to version 8.14.1-r20072.
  • Update alpine curl to version 8.19.0-r00076.
  • Update alpine rootio-curl to version 8.19.0-r00076.
  • Update debian curl to version 7.74.0-1.3+deb11u16.root.io.17.
  • Update debian rootio-curl to version 7.74.0-1.3+deb11u16.root.io.17.
  • Update debian rootio-curl to version 8.14.1-2+deb13u4.root.io.13.
  • Update debian rootio-curl to version 8.14.1-2+deb13u4.aikido.14.
  • Update debian curl to version 8.14.1-2+deb13u4.aikido.14.
  • Update curl to version 8.14.1-r20079.
  • Update rootio-curl to version 8.14.1-r20079.
  • Update curl to version 8.14.1-2+deb13u5.aikido.18.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.18.
  • Update curl to version 8.14.1-2+deb13u5.aikido.19.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.19.
  • Update curl to version 8.14.1-r30075.
  • Update rootio-curl to version 8.14.1-r30075.
  • Update curl to version 8.14.1-r20074.
  • Update rootio-curl to version 8.14.1-r20074.
  • Update curl to version 8.14.1-r200710.
  • Update rootio-curl to version 8.14.1-r200710.
  • Update curl to version 8.14.1-r30076.
  • Update rootio-curl to version 8.14.1-r30076.
  • Update curl to version 7.88.1-10+deb12u15.aikido.16.
  • Update rootio-curl to version 7.88.1-10+deb12u15.aikido.16.
  • Update curl to version 8.14.1-r200711.
  • Update rootio-curl to version 8.14.1-r200711.
  • Update curl to version 8.14.1-r30077.
  • Update rootio-curl to version 8.14.1-r30077.
  • Update curl to version 8.5.0-r00073.
  • Update rootio-curl to version 8.5.0-r00073.
  • Update curl to version 8.14.1-r20075.
  • Update rootio-curl to version 8.14.1-r20075.
  • Update curl to version 8.14.1-2+deb13u5.aikido.20.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.20.
  • Update haxx curl to version 8.21.0 or later.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:Pro:14.04:LTS canonical curl < 7.35.0-1ubuntu2.20+esm20
Fix: upgrade to 7.35.0-1ubuntu2.20+esm20
Ubuntu:Pro:16.04:LTS canonical curl < 7.47.0-1ubuntu2.19+esm16
Fix: upgrade to 7.47.0-1ubuntu2.19+esm16
Ubuntu:Pro:18.04:LTS canonical curl < 7.58.0-2ubuntu3.24+esm9
Fix: upgrade to 7.58.0-2ubuntu3.24+esm9
Ubuntu:Pro:20.04:LTS canonical curl < 7.68.0-1ubuntu2.25+esm4
Fix: upgrade to 7.68.0-1ubuntu2.25+esm4
Ubuntu:22.04:LTS canonical curl < 7.81.0-1ubuntu1.25
Fix: upgrade to 7.81.0-1ubuntu1.25
Ubuntu:24.04:LTS canonical curl < 8.5.0-2ubuntu10.10
Fix: upgrade to 8.5.0-2ubuntu10.10
Ubuntu:25.10 canonical curl < 8.14.1-2ubuntu1.4
Fix: upgrade to 8.14.1-2ubuntu1.4
Ubuntu:26.04:LTS canonical curl < 8.18.0-1ubuntu2.2
Fix: upgrade to 8.18.0-1ubuntu2.2
– curl curl <= 8.20.0
< 8.14.2
< 5c225384b8d52c67ce8259c6e4203bc57aacb567
8.20.0
Alpaquita:stream bellsoft curl >= 8.1.2-r0, < 8.21.0-r0
Fix: upgrade to 8.21.0-r0
Debian:11 debian curl All versions
Debian:12 debian curl All versions
Debian:13 debian curl All versions
Debian:14 debian curl < 8.21.0~rc2-1
Fix: upgrade to 8.21.0~rc2-1
Root:Debian:12 debian rootio-curl < 7.88.1-10+deb12u15.aikido.13
Fix: upgrade to 7.88.1-10+deb12u15.aikido.13
Root:Alpine:3.23 alpine curl < 8.19.0-r00074
< 8.19.0-r00076
Fix: upgrade to 8.19.0-r00074
Root:Alpine:3.23 alpine rootio-curl < 8.19.0-r00074
< 8.19.0-r00076
Fix: upgrade to 8.19.0-r00074
Root:Alpine:3.21 alpine curl < 8.14.1-r20071
< 8.14.1-r20072
Fix: upgrade to 8.14.1-r20071
Root:Alpine:3.21 alpine rootio-curl < 8.14.1-r20071
< 8.14.1-r20072
Fix: upgrade to 8.14.1-r20071
Root:Alpine:3.22 alpine curl < 8.14.1-r20071
< 8.14.1-r20074
Fix: upgrade to 8.14.1-r20071
Root:Alpine:3.22 alpine rootio-curl < 8.14.1-r20071
< 8.14.1-r20074
Fix: upgrade to 8.14.1-r20071
BellSoft Hardened Containers:stream bellsoft curl >= 8.1.2-r0, < 8.21.0-r0
Fix: upgrade to 8.21.0-r0
Root:Alpine:3.20 alpine rootio-curl < 8.14.1-r20077
< 8.14.1-r20078
< 8.14.1-r20071
Fix: upgrade to 8.14.1-r20077
Root:Alpine:3.20 alpine curl < 8.14.1-r20078
< 8.14.1-r20071
< 8.14.1-r20077
Fix: upgrade to 8.14.1-r20078
Root:Debian:11 debian curl < 7.74.0-1.3+deb11u16.root.io.17
Fix: upgrade to 7.74.0-1.3+deb11u16.root.io.17
Root:Debian:11 debian rootio-curl < 7.74.0-1.3+deb11u16.root.io.17
Fix: upgrade to 7.74.0-1.3+deb11u16.root.io.17
Root:Debian:13 debian rootio-curl < 8.14.1-2+deb13u4.root.io.13
< 8.14.1-2+deb13u4.aikido.14
Fix: upgrade to 8.14.1-2+deb13u4.root.io.13
Root:Debian:13 debian curl < 8.14.1-2+deb13u4.aikido.14
Fix: upgrade to 8.14.1-2+deb13u4.aikido.14
Root:Alpine:3.20 – curl < 8.14.1-r20079
< 8.14.1-r200710
< 8.14.1-r200711
Fix: upgrade to 8.14.1-r20079
Root:Alpine:3.20 – rootio-curl < 8.14.1-r20079
< 8.14.1-r200710
< 8.14.1-r200711
Fix: upgrade to 8.14.1-r20079
Root:Debian:13 – curl < 8.14.1-2+deb13u5.aikido.18
< 8.14.1-2+deb13u5.aikido.19
< 8.14.1-2+deb13u5.aikido.20
Fix: upgrade to 8.14.1-2+deb13u5.aikido.18
Root:Debian:13 – rootio-curl < 8.14.1-2+deb13u5.aikido.18
< 8.14.1-2+deb13u5.aikido.19
< 8.14.1-2+deb13u5.aikido.20
Fix: upgrade to 8.14.1-2+deb13u5.aikido.18
– haxx curl >= 7.12.0, < 8.21.0
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
Root:Alpine:3.22 – curl < 8.14.1-r30075
< 8.14.1-r30076
< 8.14.1-r30077
Fix: upgrade to 8.14.1-r30075
Root:Alpine:3.22 – rootio-curl < 8.14.1-r30075
< 8.14.1-r30076
< 8.14.1-r30077
Fix: upgrade to 8.14.1-r30075
Root:Alpine:3.21 – curl < 8.14.1-r20074
< 8.14.1-r20075
Fix: upgrade to 8.14.1-r20074
Root:Alpine:3.21 – rootio-curl < 8.14.1-r20074
< 8.14.1-r20075
Fix: upgrade to 8.14.1-r20074
Root:Debian:12 – curl < 7.88.1-10+deb12u15.aikido.16
Fix: upgrade to 7.88.1-10+deb12u15.aikido.16
Root:Debian:12 – rootio-curl < 7.88.1-10+deb12u15.aikido.16
Fix: upgrade to 7.88.1-10+deb12u15.aikido.16
Root:Alpine:3.15 – curl < 8.5.0-r00073
Fix: upgrade to 8.5.0-r00073
Root:Alpine:3.15 – rootio-curl < 8.5.0-r00073
Fix: upgrade to 8.5.0-r00073
Original advisory text
CVE-2026-8927 in curl - Patched by Root
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
Severity
9.1 Critical
CVSS 3.1: 9.1 (OSV)
Exploitation
EPSS <1%
Type
CWE-294Authentication Bypass by Capture-replay
Timeline
Published24 Jun 2026
Updated27 Sep 2026
First seen24 Jun 2026
Track software like this
Free during beta