๐Ÿ” CVE Alert

CVE-2026-9079

CRITICAL 9.8

stale proxy password leak

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

CWE CWE-522
Vendor curl
Product curl
Published Jul 3, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for curl curl

Be the first to know when new critical vulnerabilities affecting curl curl are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

curl / curl
8.8.0 < 8.14.2 8.15.0 < 8.16.1 8.17.0 < 8.20.1
curl / curl
d5e83eb745762f48d8fafadc5df5dd3ae8d8941e < 88c7e16cceec816a2df45c899d49b1e85513f193
curl / curl
8.20.0 8.19.0 8.18.0 8.17.0 8.16.0 8.15.0 8.14.1 8.14.0 8.13.0 8.12.1 8.12.0 8.11.1 8.11.0 8.10.1 8.10.0 8.9.1 8.9.0 8.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
curl.se: https://curl.se/docs/CVE-2026-9079.json curl.se: https://curl.se/docs/CVE-2026-9079.html hackerone.com: https://hackerone.com/reports/3750295

Credits

Guannan Wang Zhanpeng Liu Jiashuo Liang Guancheng Li Daniel Stenberg