TECHEPAGES[verified]@techepagesPatch
Debian 13.6 includes patches for nine curl CVEs, addressing issues like token and credential leaks, authentication bypasses, and proxy auth bypass.
Open Source Security mailing list@oss_securityPatch
Four low‑to‑medium CVEs have been fixed in curl, covering HTTP Negotiate reuse, token leaks, proxy credential reuse, and a use‑after‑free in SMB; no PoC or active exploitation is discussed.
草薙 沙耶(KUSANAGI)@kusanagi_sayaPatch
Kusanagi-curl module update 8.19.0-1 includes patches for four CVEs, providing remediation for the identified vulnerabilities.
H1 Disclosed - Public Disclosures@h1DisclosedDisclosure
User "nobcoder" publicly disclosed CVE-2026-3784, a low‑severity flaw involving improper proxy credential reuse, and shared a HackerOne link for further details.
CVE@CVEnewDisclosure
The passage discloses that curl can incorrectly reuse a proxy connection using stale credentials, potentially leaking authentication details. No proof‑of‑concept, active exploitation, or patch information is provided.
草薙 沙耶(KUSANAGI)@kusanagi_sayaPatch
The Kusanagi 9 module update addresses CVE‑2026‑3805, CVE‑2026‑3784, CVE‑2026‑3783, and CVE‑2026‑1965 by applying patches to the curl module.
DailyCVE@dailycveGeneral
The snippet simply lists the CVE identifier and its severity assessment without providing further technical or operational details.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashGeneral
The alert identifies CVE-2026-3784 as a credential-usage flaw in proxy connections, but provides no PoC, exploit, or patch details.