Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-8927

Опубликовано: 03 июл. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.1

Описание

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against proxyA using Digest auth, a subsequent transfer routed through proxyB erroneously leaks the Proxy-Authorization: header intended solely for proxyA.

РелизСтатусПримечание
devel

needed

esm-infra-legacy/trusty

released

7.35.0-1ubuntu2.20+esm20
esm-infra-legacy/xenial

released

7.47.0-1ubuntu2.19+esm16
esm-infra/bionic

released

7.58.0-2ubuntu3.24+esm9
esm-infra/focal

released

7.68.0-1ubuntu2.25+esm4
jammy

released

7.81.0-1ubuntu1.25
noble

released

8.5.0-2ubuntu10.10
questing

released

8.14.1-2ubuntu1.4
resolute

released

8.18.0-1ubuntu2.2
upstream

pending

8.21.0

Показывать по

EPSS

Процентиль: 51%
0.00752
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
28 дней назад

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.

CVSS3: 9.1
nvd
28 дней назад

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.

CVSS3: 5.3
msrc
25 дней назад

env-set cross-proxy Digest auth state leak

CVSS3: 9.1
debian
28 дней назад

When reusing a libcurl handle for sequential transfers driven by envir ...

CVSS3: 9.1
github
28 дней назад

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.

EPSS

Процентиль: 51%
0.00752
Низкий

9.1 Critical

CVSS3