Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9079

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

A flaw was found in curl. When libcurl is instructed to clear proxy authentication credentials, it fails to do so, leaving the old credentials available. This could lead to the unintended reuse of sensitive proxy authentication credentials for subsequent network transfers, potentially resulting in unauthorized access or information disclosure.

Отчет

Important: A flaw in libcurl's proxy authentication credential management can lead to information disclosure. There are no integrity or availability risks posed by this flaw.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8dotnet8.0Not affected
Red Hat Hardened ImagescurlAffected
Red Hat JBoss Core Serviceslibcurl-1.dllAffected
Red Hat JBoss Core Serviceslibcurl.soAffected
Red Hat Hardened Imagesrust-main-1.96.1-1.hum1FixedRHSA-2026:3497502.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-212
https://bugzilla.redhat.com/show_bug.cgi?id=2496771libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials

EPSS

Процентиль: 44%
0.00584
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
28 дней назад

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

CVSS3: 9.8
nvd
28 дней назад

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

msrc
25 дней назад

stale proxy password leak

CVSS3: 9.8
debian
28 дней назад

libcurl had a flaw that when instructed to clear proxy authentication ...

CVSS3: 9.8
github
28 дней назад

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

EPSS

Процентиль: 44%
0.00584
Низкий

7.5 High

CVSS3