Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-8927: curl may send proxy credentials to wrong server
CVE-2026-8927 · published 3 months ago
Summary
The curl tool can accidentally attach authentication information meant for one proxy to a request that goes through a different proxy. This could let the second proxy see credentials that were intended only for the first proxy. Update curl to the latest version to stop the credential leakage.
What to do
- Update canonical curl to version 7.35.0-1ubuntu2.20+esm20.
- Update canonical curl to version 7.47.0-1ubuntu2.19+esm16.
- Update canonical curl to version 7.58.0-2ubuntu3.24+esm9.
- Update canonical curl to version 7.68.0-1ubuntu2.25+esm4.
- Update canonical curl to version 7.81.0-1ubuntu1.25.
- Update canonical curl to version 8.5.0-2ubuntu10.10.
- Update canonical curl to version 8.14.1-2ubuntu1.4.
- Update canonical curl to version 8.18.0-1ubuntu2.2.
- Update bellsoft curl to version 8.21.0-r0.
- Update debian curl to version 8.21.0~rc2-1.
- Update debian rootio-curl to version 7.88.1-10+deb12u15.aikido.13.
- Update alpine curl to version 8.19.0-r00074.
- Update alpine rootio-curl to version 8.19.0-r00074.
- Update alpine curl to version 8.14.1-r20071.
- Update alpine rootio-curl to version 8.14.1-r20071.
- Update alpine curl to version 8.14.1-r20072.
- Update alpine curl to version 8.14.1-r20074.
- Update alpine rootio-curl to version 8.14.1-r20074.
- Update alpine rootio-curl to version 8.14.1-r20077.
- Update alpine curl to version 8.14.1-r20078.
- Update alpine rootio-curl to version 8.14.1-r20078.
- Update alpine curl to version 8.14.1-r20077.
- Update alpine rootio-curl to version 8.14.1-r20072.
- Update alpine curl to version 8.19.0-r00076.
- Update alpine rootio-curl to version 8.19.0-r00076.
- Update debian curl to version 7.74.0-1.3+deb11u16.root.io.17.
- Update debian rootio-curl to version 7.74.0-1.3+deb11u16.root.io.17.
- Update debian rootio-curl to version 8.14.1-2+deb13u4.root.io.13.
- Update debian rootio-curl to version 8.14.1-2+deb13u4.aikido.14.
- Update debian curl to version 8.14.1-2+deb13u4.aikido.14.
- Update curl to version 8.14.1-r20079.
- Update rootio-curl to version 8.14.1-r20079.
- Update curl to version 8.14.1-2+deb13u5.aikido.18.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.18.
- Update curl to version 8.14.1-2+deb13u5.aikido.19.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.19.
- Update curl to version 8.14.1-r30075.
- Update rootio-curl to version 8.14.1-r30075.
- Update curl to version 8.14.1-r20074.
- Update rootio-curl to version 8.14.1-r20074.
- Update curl to version 8.14.1-r200710.
- Update rootio-curl to version 8.14.1-r200710.
- Update curl to version 8.14.1-r30076.
- Update rootio-curl to version 8.14.1-r30076.
- Update curl to version 7.88.1-10+deb12u15.aikido.16.
- Update rootio-curl to version 7.88.1-10+deb12u15.aikido.16.
- Update curl to version 8.14.1-r200711.
- Update rootio-curl to version 8.14.1-r200711.
- Update curl to version 8.14.1-r30077.
- Update rootio-curl to version 8.14.1-r30077.
- Update curl to version 8.5.0-r00073.
- Update rootio-curl to version 8.5.0-r00073.
- Update curl to version 8.14.1-r20075.
- Update rootio-curl to version 8.14.1-r20075.
- Update curl to version 8.14.1-2+deb13u5.aikido.20.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.20.
- Update haxx curl to version 8.21.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:Pro:14.04:LTS | canonical | curl |
< 7.35.0-1ubuntu2.20+esm20 Fix: upgrade to 7.35.0-1ubuntu2.20+esm20
|
| Ubuntu:Pro:16.04:LTS | canonical | curl |
< 7.47.0-1ubuntu2.19+esm16 Fix: upgrade to 7.47.0-1ubuntu2.19+esm16
|
| Ubuntu:Pro:18.04:LTS | canonical | curl |
< 7.58.0-2ubuntu3.24+esm9 Fix: upgrade to 7.58.0-2ubuntu3.24+esm9
|
| Ubuntu:Pro:20.04:LTS | canonical | curl |
< 7.68.0-1ubuntu2.25+esm4 Fix: upgrade to 7.68.0-1ubuntu2.25+esm4
|
| Ubuntu:22.04:LTS | canonical | curl |
< 7.81.0-1ubuntu1.25 Fix: upgrade to 7.81.0-1ubuntu1.25
|
| Ubuntu:24.04:LTS | canonical | curl |
< 8.5.0-2ubuntu10.10 Fix: upgrade to 8.5.0-2ubuntu10.10
|
| Ubuntu:25.10 | canonical | curl |
< 8.14.1-2ubuntu1.4 Fix: upgrade to 8.14.1-2ubuntu1.4
|
| Ubuntu:26.04:LTS | canonical | curl |
< 8.18.0-1ubuntu2.2 Fix: upgrade to 8.18.0-1ubuntu2.2
|
| – | curl | curl |
<= 8.20.0 < 8.14.2 < 5c225384b8d52c67ce8259c6e4203bc57aacb567 8.20.0 |
| Alpaquita:stream | bellsoft | curl |
>= 8.1.2-r0, < 8.21.0-r0 Fix: upgrade to 8.21.0-r0
|
| Debian:11 | debian | curl | All versions |
| Debian:12 | debian | curl | All versions |
| Debian:13 | debian | curl | All versions |
| Debian:14 | debian | curl |
< 8.21.0~rc2-1 Fix: upgrade to 8.21.0~rc2-1
|
| Root:Debian:12 | debian | rootio-curl |
< 7.88.1-10+deb12u15.aikido.13 Fix: upgrade to 7.88.1-10+deb12u15.aikido.13
|
| Root:Alpine:3.23 | alpine | curl |
< 8.19.0-r00074 < 8.19.0-r00076 Fix: upgrade to 8.19.0-r00074
|
| Root:Alpine:3.23 | alpine | rootio-curl |
< 8.19.0-r00074 < 8.19.0-r00076 Fix: upgrade to 8.19.0-r00074
|
| Root:Alpine:3.21 | alpine | curl |
< 8.14.1-r20071 < 8.14.1-r20072 Fix: upgrade to 8.14.1-r20071
|
| Root:Alpine:3.21 | alpine | rootio-curl |
< 8.14.1-r20071 < 8.14.1-r20072 Fix: upgrade to 8.14.1-r20071
|
| Root:Alpine:3.22 | alpine | curl |
< 8.14.1-r20071 < 8.14.1-r20074 Fix: upgrade to 8.14.1-r20071
|
| Root:Alpine:3.22 | alpine | rootio-curl |
< 8.14.1-r20071 < 8.14.1-r20074 Fix: upgrade to 8.14.1-r20071
|
| BellSoft Hardened Containers:stream | bellsoft | curl |
>= 8.1.2-r0, < 8.21.0-r0 Fix: upgrade to 8.21.0-r0
|
| Root:Alpine:3.20 | alpine | rootio-curl |
< 8.14.1-r20077 < 8.14.1-r20078 < 8.14.1-r20071 Fix: upgrade to 8.14.1-r20077
|
| Root:Alpine:3.20 | alpine | curl |
< 8.14.1-r20078 < 8.14.1-r20071 < 8.14.1-r20077 Fix: upgrade to 8.14.1-r20078
|
| Root:Debian:11 | debian | curl |
< 7.74.0-1.3+deb11u16.root.io.17 Fix: upgrade to 7.74.0-1.3+deb11u16.root.io.17
|
| Root:Debian:11 | debian | rootio-curl |
< 7.74.0-1.3+deb11u16.root.io.17 Fix: upgrade to 7.74.0-1.3+deb11u16.root.io.17
|
| Root:Debian:13 | debian | rootio-curl |
< 8.14.1-2+deb13u4.root.io.13 < 8.14.1-2+deb13u4.aikido.14 Fix: upgrade to 8.14.1-2+deb13u4.root.io.13
|
| Root:Debian:13 | debian | curl |
< 8.14.1-2+deb13u4.aikido.14 Fix: upgrade to 8.14.1-2+deb13u4.aikido.14
|
| Root:Alpine:3.20 | – | curl |
< 8.14.1-r20079 < 8.14.1-r200710 < 8.14.1-r200711 Fix: upgrade to 8.14.1-r20079
|
| Root:Alpine:3.20 | – | rootio-curl |
< 8.14.1-r20079 < 8.14.1-r200710 < 8.14.1-r200711 Fix: upgrade to 8.14.1-r20079
|
| Root:Debian:13 | – | curl |
< 8.14.1-2+deb13u5.aikido.18 < 8.14.1-2+deb13u5.aikido.19 < 8.14.1-2+deb13u5.aikido.20 Fix: upgrade to 8.14.1-2+deb13u5.aikido.18
|
| Root:Debian:13 | – | rootio-curl |
< 8.14.1-2+deb13u5.aikido.18 < 8.14.1-2+deb13u5.aikido.19 < 8.14.1-2+deb13u5.aikido.20 Fix: upgrade to 8.14.1-2+deb13u5.aikido.18
|
| – | haxx | curl |
>= 7.12.0, < 8.21.0 cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* |
| Root:Alpine:3.22 | – | curl |
< 8.14.1-r30075 < 8.14.1-r30076 < 8.14.1-r30077 Fix: upgrade to 8.14.1-r30075
|
| Root:Alpine:3.22 | – | rootio-curl |
< 8.14.1-r30075 < 8.14.1-r30076 < 8.14.1-r30077 Fix: upgrade to 8.14.1-r30075
|
| Root:Alpine:3.21 | – | curl |
< 8.14.1-r20074 < 8.14.1-r20075 Fix: upgrade to 8.14.1-r20074
|
| Root:Alpine:3.21 | – | rootio-curl |
< 8.14.1-r20074 < 8.14.1-r20075 Fix: upgrade to 8.14.1-r20074
|
| Root:Debian:12 | – | curl |
< 7.88.1-10+deb12u15.aikido.16 Fix: upgrade to 7.88.1-10+deb12u15.aikido.16
|
| Root:Debian:12 | – | rootio-curl |
< 7.88.1-10+deb12u15.aikido.16 Fix: upgrade to 7.88.1-10+deb12u15.aikido.16
|
| Root:Alpine:3.15 | – | curl |
< 8.5.0-r00073 Fix: upgrade to 8.5.0-r00073
|
| Root:Alpine:3.15 | – | rootio-curl |
< 8.5.0-r00073 Fix: upgrade to 8.5.0-r00073
|
Original advisory text
CVE-2026-8927 in curl - Patched by Root
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
References
- https://www.cve.org/CVERecord?id=CVE-2026-8927 Third Party Advisory
- https://curl.se/L7HzKXisfJ/CVE-2026-8927.md Third Party Advisory
- https://ubuntu.com/security/CVE-2026-8927 Third Party Advisory
- https://ubuntu.com/security/notices/USN-8487-1 Vendor Advisory
- https://docs.bell-sw.com/security/cves/CVE-2026-8927 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-8927 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8927.j... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-8927 Vendor Advisory
- https://curl.se/docs/CVE-2026-8927.html URL
- https://curl.se/docs/CVE-2026-8927.json URL
- https://github.com/curl/curl.git Product
- https://hackerone.com/reports/3744543 URL
Severity
9.1
Critical
CVSS 3.1: 9.1 (OSV)
Exploitation
EPSS <1%
Type
CWE-294Authentication Bypass by Capture-replay
Timeline
Published24 Jun 2026
Updated27 Sep 2026
First seen24 Jun 2026
Sources
UBUNTU-CVE-2026-8927 · OSV
CURL-CVE-2026-8927 · OSV
CVE-2026-8927 · NVD
CVE-2026-8927 · MITRE
BELL-CVE-2026-8927 · OSV
DEBIAN-CVE-2026-8927 · OSV
CVE-2026-8927 · OSV
Track software like this
Free during beta