{"id":"CVE-2026-9079","title":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them.","summary":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-522","CWE-212"],"vendor":"haxx","product":"curl","affected":["curl >= 8.8.0, < 8.21.0"],"patched":["curl 8.21.0"],"published":"2026-07-03","updated":"2026-09-15","sourceUpdated":"2026-09-15T07:16:34.597","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","references":[{"url":"https://curl.se/docs/CVE-2026-9079.html","label":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"url":"https://curl.se/docs/CVE-2026-9079.json","label":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"url":"https://hackerone.com/reports/3750295","label":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"url":"https://hackerone.com/reports/3750295","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9079.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-9079"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2496771"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-9079"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079"},{"url":"https://access.redhat.com/errata/RHSA-2026:29017"},{"url":"https://access.redhat.com/errata/RHSA-2026:34975"},{"url":"https://access.redhat.com/errata/RHSA-2026:56869"},{"url":"https://access.redhat.com/errata/RHSA-2026:69125"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat","score-dispute"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2026-07-06T16:49:15.639683Z"},"epss":0.00584,"epssPercentile":0.46344,"scores":{"nvd":9.8,"vendor":7.5},"ingestedAt":"2026-07-04T06:55:48.791Z","slug":"CVE-2026-9079","body":"## Overview\n\nlibcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them.\n\n## Affected\n\n- `curl >= 8.8.0, < 8.21.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `curl 8.21.0`\n\n## Vendor advisories\n\n- **RHSA-2026:29017** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:29017)\n- **RHSA-2026:34975** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:34975)\n- **RHSA-2026:56869** · Red Hat · fixed in: Red Hat JBoss Core Services 2.4.62.SP5 · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:56869)\n- **Red Hat VEX** · Moderate · affected: Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4 · no fix planned: Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9079.json)\n- **RHSA-2026:69125** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69125)","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":203506,"id":"CVE-2026-9079","ts":1789457645852,"field":"exploit_available","old":"false","new":"true"},{"seq":203505,"id":"CVE-2026-9079","ts":1789457645852,"field":"cvss","old":"7.5","new":"9.8"},{"seq":203504,"id":"CVE-2026-9079","ts":1789457645852,"field":"severity","old":"high","new":"critical"},{"seq":5546,"id":"CVE-2026-9079","ts":1788887298571,"field":"cvss","old":null,"new":"7.5"},{"seq":5545,"id":"CVE-2026-9079","ts":1788887298571,"field":"severity","old":"none","new":"high"},{"seq":4421,"id":"CVE-2026-9079","ts":1788886405031,"field":"cvss","old":"7.5","new":null},{"seq":4420,"id":"CVE-2026-9079","ts":1788886405031,"field":"severity","old":"high","new":"none"},{"seq":3254,"id":"CVE-2026-9079","ts":1788883138401,"field":"cvss","old":null,"new":"7.5"},{"seq":3253,"id":"CVE-2026-9079","ts":1788883138401,"field":"severity","old":"none","new":"high"}]}