CVE-2026-3784Patch(haxx / curl)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch haxx curl systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-305

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-12); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-03-11: 1Mentions · 2026-03-12: 2Mentions · 2026-03-13: 2Mentions · 2026-03-15: 2Mentions · 2026-07-13: 1PoC Mentioned / Linked · 2026-03-15: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 2Patch / Workaround · 2026-07-13: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-15: 2Technical Details · 2026-07-13: 103-1103-1203-1303-1507-13
Signal classification3 categories
Patch
450.0%
General
225.0%
Disclosure
225.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-111
General1
2026-03-122
General1Patch1
2026-03-132
Patch2
2026-03-152
Disclosure2
2026-07-131
Patch1
Full discourse8 posts
  • Open Source Security mailing list@oss_security
    Patch

    4 Low to Medium CVEs fixed in curl https://www.openwall.com/lists/oss-security/2026/03/11/ CVE-2026-1965: bad reuse of HTTP Negotiate connection CVE-2026-3783: token leak with redirect and netrc CVE-2026-3784: wrong proxy connection reuse with credentials CVE-2026-3805: use after free in SMB connection reuse

    Post summary

    Four low‑to‑medium CVEs have been fixed in curl, covering HTTP Negotiate reuse, token leaks, proxy credential reuse, and a use‑after‑free in SMB; no PoC or active exploitation is discussed.

    00063792
    4.4K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-curl モジュール更新情報 8.19.0-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 curl 8.19.0-1 この更新には脆弱性(CVE-2026-3805, CVE-2026-3784, CVE-2026-3783, CVE-2026-1965)への対応が含まれます。 モジュールのアップデートについては、以下のコマンドで適用可能です。 # ... https://kusanagi.tokyo/releases/23348/

    Post summary

    Kusanagi-curl module update 8.19.0-1 includes patches for four CVEs, providing remediation for the identified vulnerabilities.

    01010150
    198 followersView on X
  • TECHEPAGES@techepages
    Patch

    9 curl CVEs patched in Debian 13.6 🚨 🔵 CVE-2026-3783/6253 – token & credential leaks on redirects 🔵 CVE-2026-3805/5773 – SMB UAF & wrong reuse 🔵 CVE-2026-1965/5545 – Negotiate auth bypass 🔵 CVE-2026-3784 – proxy auth bypass (CVSS 6.5) 🔵 CVE-2026-6276 – cookie leak 🔵 CVE-2026-4873 – TLS bypass apt upgrade ⬆️

    Post summary

    Debian 13.6 includes patches for nine curl CVEs, addressing issues like token and credential leaks, authentication bypasses, and proxy auth bypass.

    0000064
    19 followersView on X
  • H1 Disclosed - Public Disclosures@h1Disclosed
    Disclosure

    ⚡ CVE-2026-3784: wrong proxy connection reuse with credentials 👨🏻‍💻 nobcoder ➟ curl 🟨 Low 💰 None 🔗 https://hackerone.com/reports/3584903 #bugbounty #bugbountytips #cybersecurity #infosec https://t.co/M80vQQKWOz

    Post summary

    User "nobcoder" publicly disclosed CVE-2026-3784, a low‑severity flaw involving improper proxy credential reuse, and shared a HackerOne link for further details.

    00000339
    10.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3784 curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper … https://www.cve.org/CVERecord?id=CVE-2026-3784

    Post summary

    The passage discloses that curl can incorrectly reuse a proxy connection using stale credentials, potentially leaking authentication details. No proof‑of‑concept, active exploitation, or patch information is provided.

    00000151
    56.7K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-curl Module Update 8.19.0-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: curl 8.19.0-1 This update includes support for vulnerability(CVE-2026-3805, CVE-2026-3784, CVE-2026-3783, CVE-2026-1965). The module... https://kusanagi.tokyo/en/releases/23349/

    Post summary

    The Kusanagi 9 module update addresses CVE‑2026‑3805, CVE‑2026‑3784, CVE‑2026‑3783, and CVE‑2026‑1965 by applying patches to the curl module.

    0000045
    198 followersView on X
  • DailyCVE@dailycve
    General

    🔵 curl (libcurl), Improper Authentication, #CVE-2026-3784 (Low) https://dailycve.com/curl-libcurl-improper-authentication-cve-2026-3784-low/

    Post summary

    The snippet simply lists the CVE identifier and its severity assessment without providing further technical or operational details.

    0000019
    168 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3784 - wrong proxy connection reuse with credentials Intel Report: https://ift.tt/cm43O1P

    Post summary

    The alert identifies CVE-2026-3784 as a credential-usage flaw in proxy connections, but provides no PoC, exploit, or patch details.

    0000021
    343 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more