PT-2026-51752 · Libcurl+2 · Libcurl+2

·

CVE-2026-9079

·

Published

2026-06-24

·

Updated

2026-08-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libcurl (affected versions not specified)
Description A flaw exists where the software fails to clear proxy authentication credentials when instructed to do so. This results in old credentials remaining available and potentially being used for subsequent transfers that should not have access to them.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91791
AZL-91848
CVE-2026-9079
JLSEC-2026-1218
OPENSUSE-SU-2026:11230-1
OPENSUSE-SU-2026:21272-1
RHSA-2026:34975
SUSE-SU-2026:22553-1
SUSE-SU-2026:22582-1
SUSE-SU-2026:22709-1
SUSE-SU-2026:22889-1
SUSE-SU-2026:2925-1
SUSE-SU-2026:2926-1
SUSE-SU-2026:3043-1
USN-8487-1

Affected Products

Linuxmint
Ubuntu
Libcurl