CVE-2026-9079: stale proxy password leak
Last updated 2 July 2026
Other sources
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 7.74.0-1.3+deb11u13Fixed in 7.74.0-1.3+deb11u16Fixed in 7.88.1-10+deb12u14Fixed in 7.88.1-10+deb12u5Fixed in 8.21.0-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.11.1-10 - Operational
Revoke/rotate any credentials (including proxy authentication credentials) that may have been exposed or left in place due to stale proxy password leak in libcurl, so subsequent transfers cannot reuse the old credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9079?
CVE-2026-9079 has a risk rating of 21, indicating a serious security vulnerability.
How do I fix CVE-2026-9079?
To fix CVE-2026-9079, update to the latest version of libcurl that addresses the stale proxy password leak.
What type of security issue is CVE-2026-9079?
CVE-2026-9079 is a security issue related to improper handling of proxy authentication credentials.
What products are affected by CVE-2026-9079?
CVE-2026-9079 affects versions of libcurl used in Debian and other systems.
When was CVE-2026-9079 published?
CVE-2026-9079 was published on July 3, 2026.