Количество 12
Количество 12
GHSA-jr4f-4564-w3mr
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
CVE-2026-8927
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
CVE-2026-8927
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
CVE-2026-8927
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
CVE-2026-8927
env-set cross-proxy Digest auth state leak
CVE-2026-8927
When reusing a libcurl handle for sequential transfers driven by envir ...
RLSA-2026:55432
Important: curl security update
ELSA-2026-55432
ELSA-2026-55432: curl security update (IMPORTANT)
openSUSE-SU-2026:21272-1
Security update for curl
SUSE-SU-2026:3043-1
Security update for curl
SUSE-SU-2026:2926-1
Security update for curl
SUSE-SU-2026:2925-1
Security update for curl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-jr4f-4564-w3mr When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`. | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`. | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`. | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-8927 env-set cross-proxy Digest auth state leak | CVSS3: 5.3 | 1% Низкий | 2 месяца назад | |
CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by envir ... | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
RLSA-2026:55432 Important: curl security update | 1% Низкий | 29 дней назад | ||
ELSA-2026-55432 ELSA-2026-55432: curl security update (IMPORTANT) | 1% Низкий | около 1 месяца назад | ||
openSUSE-SU-2026:21272-1 Security update for curl | 2 месяца назад | |||
SUSE-SU-2026:3043-1 Security update for curl | 2 месяца назад | |||
SUSE-SU-2026:2926-1 Security update for curl | 2 месяца назад | |||
SUSE-SU-2026:2925-1 Security update for curl | 2 месяца назад |
Уязвимостей на страницу