Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-8927

Опубликовано: 06 июл. 2026
Источник: msrc
CVSS3: 5.3
EPSS Низкий

Описание

env-set cross-proxy Digest auth state leak

EPSS

Процентиль: 41%
0.005
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.

CVSS3: 7.5
redhat
2 месяца назад

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.

CVSS3: 9.1
nvd
2 месяца назад

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.

CVSS3: 9.1
debian
2 месяца назад

When reusing a libcurl handle for sequential transfers driven by envir ...

rocky
29 дней назад

Important: curl security update

EPSS

Процентиль: 41%
0.005
Низкий

5.3 Medium

CVSS3