Insufficiently protected credentials in cURL - CVE-2026-9079
Published: June 24, 2026
cURL
Detailed vulnerability description
The vulnerability allows a remote user to disclose proxy authentication credentials.
The vulnerability exists due to insufficiently protected credentials in libcurl proxy authentication handling when clearing proxy authentication credentials. A remote user can reuse a handle after changing proxy credentials to disclose proxy authentication credentials.
The issue affects libcurl and does not affect the curl command line tool.