Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9079

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

A flaw was found in curl. When libcurl is instructed to clear proxy authentication credentials, it fails to do so, leaving the old credentials available. This could lead to the unintended reuse of sensitive proxy authentication credentials for subsequent network transfers, potentially resulting in unauthorized access or information disclosure.

Отчет

Important: A flaw in libcurl's proxy authentication credential management can lead to information disclosure. There are no integrity or availability risks posed by this flaw.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Affected
Red Hat Enterprise Linux 10curlAffected
Red Hat Enterprise Linux 10igvmNot affected
Red Hat Enterprise Linux 10rustNot affected
Red Hat Enterprise Linux 10s390utilsNot affected
Red Hat Enterprise Linux 10snphostNot affected
Red Hat Enterprise Linux 10trusteeNot affected
Red Hat Enterprise Linux 10trustee-guest-componentsAffected
Red Hat Enterprise Linux 6curlNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-212
https://bugzilla.redhat.com/show_bug.cgi?id=2496771libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials

EPSS

Процентиль: 62%
0.01064
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
2 месяца назад

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

CVSS3: 9.8
nvd
2 месяца назад

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

msrc
2 месяца назад

stale proxy password leak

CVSS3: 9.8
debian
2 месяца назад

libcurl had a flaw that when instructed to clear proxy authentication ...

CVSS3: 9.8
github
2 месяца назад

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

EPSS

Процентиль: 62%
0.01064
Низкий

7.5 High

CVSS3