Description


libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

Related CPE's


Vulnerable

References




https://hackerone.com/reports/3750295

ExploitIssue TrackingThird Party Advisory

https://hackerone.com/reports/3750295

ExploitIssue TrackingThird Party Advisory

Weaknesses


2499f714-1537-4658-8207-48ae4bb9eae9

Secondary

CWE-522


CWE-522

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

Information


Source identifier

2499f714-1537-4658-8207-48ae4bb9eae9

Vulnerability status

Modified

Published

2026-07-03T07:16:25.620Z

3 months ago

Last modified

2026-09-15T07:16:34.597Z

3 weeks ago