Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-9079: libcurl Leaks Old Proxy Passwords

CURL-CVE-2026-9079 CVE-2026-9079 CVE-2026-9079
Summary

libcurl, a software used for internet transfers, has a flaw that can expose old proxy passwords. This is a concern because it allows unauthorized access to proxy servers. To protect your systems, update libcurl to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
curl curl <= 8.20.0
Original title
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not kn...
Original description
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
Vulnerability type
CWE-522 Insufficiently Protected Credentials
Published: 3 Jul 2026 · Updated: 23 Jul 2026 · First seen: 24 Jun 2026