Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8927

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against proxyA using Digest auth, a subsequent transfer routed through proxyB erroneously leaks the Proxy-Authorization: header intended solely for proxyA.

A flaw was found in libcurl. When reusing a libcurl handle for sequential transfers with environment-variable proxy configuration, the library does not properly clear the proxy authentication state. This oversight can lead to the unintended disclosure of Proxy-Authorization headers to an incorrect proxy, potentially exposing sensitive authentication information to an unauthorized entity. This is an information disclosure vulnerability.

Отчет

This Important information disclosure vulnerability in libcurl arises when a handle is reused for sequential transfers with environment-variable proxy configurations, failing to clear the proxy authentication state. This oversight can lead to Proxy-Authorization headers being inadvertently sent to an incorrect proxy, potentially exposing sensitive authentication information in Red Hat environments utilizing multiple proxy configurations. This flaw leads only to a confidentiality impact. There has been no observed integrity impact.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9Under investigation
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Under investigation
Red Hat Enterprise Linux 10curlAffected
Red Hat Enterprise Linux 10igvmUnder investigation
Red Hat Enterprise Linux 10rustUnder investigation
Red Hat Enterprise Linux 10s390utilsUnder investigation
Red Hat Enterprise Linux 10snphostUnder investigation
Red Hat Enterprise Linux 10trusteeUnder investigation
Red Hat Enterprise Linux 10trustee-guest-componentsUnder investigation
Red Hat Enterprise Linux 6curlUnder investigation

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2496769curl: Information disclosure due to uncleared proxy authentication state

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
28 дней назад

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.

CVSS3: 9.1
nvd
28 дней назад

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.

CVSS3: 5.3
msrc
25 дней назад

env-set cross-proxy Digest auth state leak

CVSS3: 9.1
debian
28 дней назад

When reusing a libcurl handle for sequential transfers driven by envir ...

CVSS3: 9.1
github
28 дней назад

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.

7.5 High

CVSS3