WindowsForum[verified]@windowsforumGeneral
The post highlights a medium‑severity vulnerability (CVE‑2026‑7168) where reusing a libcurl handle can leak Digest Proxy‑Authorization credentials between proxies, but no PoC, exploit, or active‑use evidence is provided.
H1 Disclosed - Public Disclosures@h1DisclosedDisclosure
The tweet announces CVE‑2026‑7168, a Medium‑severity cross‑proxy Digest authentication state leak, linking to a HackerOne bounty report but providing no exploits, patches, or evidence of active exploitation.
草薙 沙耶(KUSANAGI)@kusanagi_sayaPatch
The kusanagi‑curl module is updated to version 8.20.0‑1, providing patches for the listed CVEs.
H1 Disclosed - Public Disclosures@h1DisclosedPatch
The tweet announces that libcurl 8.20.0’s fix for CVE-2026-7168 is incomplete, noting that altering CURLOPT_PROXYPORT still leaks stale proxy data, and it links to a HackerOne bounty report for more detail.
Open Source Security mailing list@oss_securityGeneral
The post lists several CVE identifiers for curl, each describing a type of credential or state leak, but lacks additional context such as PoC, exploits, patches, or active exploitation details.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The post merely cites CVE-2026-7168 and links to a vulnerability advisory, offering no substantive details or claims beyond that.
草薙 沙耶(KUSANAGI)@kusanagi_sayaPatch
The KUSANAGI 9 module update to curl 8.20.0-1 provides fixes for several CVEs, addressing vulnerabilities such as CVE-2026-7168, CVE-2026-7009, CVE-2026-6429, CVE-2026-6276, and CVE-2026-6253.
Autumn Good@autumn_good_35Disclosure
The post announces eight new CVE entries for curl/libcurl and directs readers to curl’s official security page.