Critical severity9.8NVD Advisory· Published Jul 3, 2026· Updated Sep 15, 2026
CVE-2026-9079
CVE-2026-9079
Description
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19- osv-coords16 versionspkg:apk/chainguard/eco-python-curlpkg:apk/chainguard/eco-python-curl-minimalpkg:apk/chainguard/eco-python-curl-minimal-binpkg:apk/chainguard/eco-python-curl-minimal-devpkg:apk/chainguard/eco-python-curl-minimal-docpkg:apk/chainguard/eco-python-curl-minimal-staticpkg:apk/chainguard/eco-python-curl-nghttp2pkg:apk/chainguard/eco-python-curl-nghttp2-binpkg:apk/chainguard/eco-python-curl-nghttp2-devpkg:apk/chainguard/eco-python-curl-nghttp2-staticpkg:rpm/almalinux/curlpkg:rpm/almalinux/libcurlpkg:rpm/almalinux/libcurl-develpkg:rpm/almalinux/libcurl-minimalpkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweed
< 8.21.0-r0+ 15 more
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.21.0-r0
- (no CPE)range: < 8.12.1-4.el10_2.6
- (no CPE)range: < 8.12.1-4.el10_2.6
- (no CPE)range: < 8.12.1-4.el10_2.6
- (no CPE)range: < 8.12.1-4.el10_2.6
- (no CPE)range: < 8.14.1-160000.8.1
- (no CPE)range: < 8.21.0-1.1
Patches
Vulnerability mechanics
References
3- curl.se/docs/CVE-2026-9079.htmlnvdPatchVendor Advisory
- hackerone.com/reports/3750295nvdExploitIssue TrackingThird Party Advisory
- curl.se/docs/CVE-2026-9079.jsonnvdVendor Advisory
News mentions
1- 25-Year-Old Vulnerability in cURL Used by 30 Billion Devices Finally PatchedCyber Security News · Jun 25, 2026