Back

CRITICAL

stale proxy password leak

Published Jul 3, 2026

Description

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

Affected products

Remediation

Red Hat statement

Important: A flaw in libcurl's proxy authentication credential management can lead to information disclosure. There are no integrity or availability risks posed by this flaw.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner curl
Published Jul 3, 2026
Updated Sep 15, 2026
Reserved May 20, 2026
CISA Vulnrichment
Updated Jul 6, 2026
NVD
Status Modified
Modified Sep 15, 2026
Red Hat
Severity Moderate
Public date Jul 3, 2026