stale proxy password leak
Published Jul 3, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.58%
Description
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.
Affected products
-
- Version 8.10.0StatusaffectedConstraints-
- Version 8.10.1StatusaffectedConstraints-
- Version 8.11.0StatusaffectedConstraints-
- Version 8.11.1StatusaffectedConstraints-
- Version 8.12.0StatusaffectedConstraints-
- Version 8.12.1StatusaffectedConstraints-
- Version 8.13.0StatusaffectedConstraints-
- Version 8.14.0StatusaffectedConstraints-
- Version 8.14.1StatusaffectedConstraints-
- Version 8.15.0StatusaffectedConstraints<8.16.1
- Version 8.15.0StatusaffectedConstraints-
- Version 8.16.0StatusaffectedConstraints-
- Version 8.17.0StatusaffectedConstraints<8.20.1
- Version 8.17.0StatusaffectedConstraints-
- Version 8.18.0StatusaffectedConstraints-
- Version 8.19.0StatusaffectedConstraints-
- Version 8.20.0StatusaffectedConstraints-
- Version 8.8.0StatusaffectedConstraints<8.14.2
- Version 8.8.0StatusaffectedConstraints-
- Version 8.9.0StatusaffectedConstraints-
- Version 8.9.1StatusaffectedConstraints-
- Version
-
- Version StatusaffectedConstraints
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Curl | Curl | unaffected |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Curl | Curl | unaffected |
|
No data.
Red Hat Enterprise Linux 10
curl-0:8.12.1-4.el10_2.6
Fixed · RHSA-2026:69125
Red Hat Hardened Images
curl-main-8.21.0-0.1.hum1
Fixed · RHSA-2026:29017
Red Hat Hardened Images
rust-main-1.96.1-1.hum1
Fixed · RHSA-2026:34975
Confidential Compute Attestation
build-of-trustee/trustee-rhel9
Affected
Confidential Compute Attestation
openshift-sandboxed-containers/osc-podvm-payload-rhel9
Affected
Red Hat Enterprise Linux 10
igvm
Not affected
Red Hat Enterprise Linux 10
rust
Not affected
Red Hat Enterprise Linux 10
s390utils
Not affected
Red Hat Enterprise Linux 10
snphost
Not affected
Red Hat Enterprise Linux 10
trustee
Not affected
Red Hat Enterprise Linux 10
trustee-guest-components
Affected
Red Hat Enterprise Linux 6
curl
Not affected
Red Hat Enterprise Linux 7
curl
Not affected
Red Hat Enterprise Linux 8
curl
Not affected
Red Hat Enterprise Linux 8
dotnet8.0
Not affected
Red Hat Enterprise Linux 9
curl
Not affected
Red Hat Enterprise Linux 9
rust
Not affected
Red Hat Enterprise Linux 9
snphost
Not affected
Red Hat Enterprise Linux 9
trustee-guest-components
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rust
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Affected
Red Hat OpenShift Dev Spaces
devspaces/code-rhel9
Not affected
Red Hat Trusted Profile Analyzer
rhtpa/rhtpa-trustification-service-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | curl-0:8.12.1-4.el10_2.6 | Fixed | RHSA-2026:69125 |
| Red Hat Hardened Images | curl-main-8.21.0-0.1.hum1 | Fixed | RHSA-2026:29017 |
| Red Hat Hardened Images | rust-main-1.96.1-1.hum1 | Fixed | RHSA-2026:34975 |
| Confidential Compute Attestation | build-of-trustee/trustee-rhel9 | Affected | n/a |
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux 10 | igvm | Not affected | n/a |
| Red Hat Enterprise Linux 10 | rust | Not affected | n/a |
| Red Hat Enterprise Linux 10 | s390utils | Not affected | n/a |
| Red Hat Enterprise Linux 10 | snphost | Not affected | n/a |
| Red Hat Enterprise Linux 10 | trustee | Not affected | n/a |
| Red Hat Enterprise Linux 10 | trustee-guest-components | Affected | n/a |
| Red Hat Enterprise Linux 6 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dotnet8.0 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 9 | rust | Not affected | n/a |
| Red Hat Enterprise Linux 9 | snphost | Not affected | n/a |
| Red Hat Enterprise Linux 9 | trustee-guest-components | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rust | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/code-rhel9 | Not affected | n/a |
| Red Hat Trusted Profile Analyzer | rhtpa/rhtpa-trustification-service-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Important: A flaw in libcurl's proxy authentication credential management can lead to information disclosure. There are no integrity or availability risks posed by this flaw.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Jul 6, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Jul–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.58% (0.00584) | 46.00th | v5 (v2026.06.15) |
| Jul 4, 2026 | 0.25% (0.00250) | 16.23th | v5 (v2026.06.15) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-9079 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2496771 Issue Tracking
- https://curl.se/docs/CVE-2026-9079.html PatchVendor Advisory
- https://curl.se/docs/CVE-2026-9079.json Vendor Advisory
- https://hackerone.com/reports/3750295 exploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-9079
- https://www.cve.org/CVERecord?id=CVE-2026-9079
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-9079 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2496771 | Issue Tracking | |
| https://curl.se/docs/CVE-2026-9079.html | PatchVendor Advisory | |
| https://curl.se/docs/CVE-2026-9079.json | Vendor Advisory | |
| https://hackerone.com/reports/3750295 | exploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-9079 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-9079 |
Change history (0)
No recorded changes yet.