Количество 10
Количество 10
CVE-2026-8927
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
CVE-2026-8927
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
CVE-2026-8927
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
CVE-2026-8927
env-set cross-proxy Digest auth state leak
CVE-2026-8927
When reusing a libcurl handle for sequential transfers driven by envir ...
GHSA-jr4f-4564-w3mr
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
openSUSE-SU-2026:21272-1
Security update for curl
SUSE-SU-2026:3043-1
Security update for curl
SUSE-SU-2026:2926-1
Security update for curl
SUSE-SU-2026:2925-1
Security update for curl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`. | CVSS3: 9.1 | 1% Низкий | 28 дней назад | |
CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`. | CVSS3: 7.5 | 1% Низкий | 28 дней назад | |
CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`. | CVSS3: 9.1 | 1% Низкий | 28 дней назад | |
CVE-2026-8927 env-set cross-proxy Digest auth state leak | CVSS3: 5.3 | 1% Низкий | 25 дней назад | |
CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by envir ... | CVSS3: 9.1 | 1% Низкий | 28 дней назад | |
GHSA-jr4f-4564-w3mr When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`. | CVSS3: 9.1 | 1% Низкий | 28 дней назад | |
openSUSE-SU-2026:21272-1 Security update for curl | 23 дня назад | |||
SUSE-SU-2026:3043-1 Security update for curl | 16 дней назад | |||
SUSE-SU-2026:2926-1 Security update for curl | 17 дней назад | |||
SUSE-SU-2026:2925-1 Security update for curl | 17 дней назад |
Уязвимостей на страницу