---
id: CVE-2026-9079
title: |-
  libcurl had a flaw that when instructed to clear proxy authentication
  credentials which made it not do so, leaving the old credentials around to get
  used for subsequent transfers that should not know nor use them.
summary: |-
  libcurl had a flaw that when instructed to clear proxy authentication
  credentials which made it not do so, leaving the old credentials around to get
  used for subsequent transfers that should not know nor use them.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-522
  - CWE-212
vendor: haxx
product: curl
affected:
  - 'curl >= 8.8.0, < 8.21.0'
patched:
  - curl 8.21.0
published: '2026-07-03'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T07:16:34.597'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9079'
references:
  - url: 'https://curl.se/docs/CVE-2026-9079.html'
    label: 2499f714-1537-4658-8207-48ae4bb9eae9
  - url: 'https://curl.se/docs/CVE-2026-9079.json'
    label: 2499f714-1537-4658-8207-48ae4bb9eae9
  - url: 'https://hackerone.com/reports/3750295'
    label: 2499f714-1537-4658-8207-48ae4bb9eae9
  - url: 'https://hackerone.com/reports/3750295'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9079.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-9079'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2496771'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-9079'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9079'
  - url: 'https://access.redhat.com/errata/RHSA-2026:29017'
  - url: 'https://access.redhat.com/errata/RHSA-2026:34975'
  - url: 'https://access.redhat.com/errata/RHSA-2026:56869'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
  - score-dispute
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-07-06T16:49:15.639683Z'
epss: 0.00584
epssPercentile: 0.46344
scores:
  nvd: 9.8
  vendor: 7.5
ingestedAt: '2026-07-04T06:55:48.791Z'
---

## Overview

libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.

## Affected

- `curl >= 8.8.0, < 8.21.0`

## Remediation

Upgrade past the affected range:

- `curl 8.21.0`

## Vendor advisories

- **RHSA-2026:29017** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:29017)
- **RHSA-2026:34975** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:34975)
- **RHSA-2026:56869** · Red Hat · fixed in: Red Hat JBoss Core Services 2.4.62.SP5 · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:56869)
- **Red Hat VEX** · Moderate · affected: Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4 · no fix planned: Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9079.json)
