CVE-2026-9079Disclosure(haxx / curl)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch haxx curl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-03: 1Mentions · 2026-07-07: 1Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-07: 107-0307-07
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-031
Disclosure1
2026-07-071
Patch1
Full discourse2 posts
  • 宝玉@dotey
    Disclosure

    《阿图因 AI 在 CyberGym 测试中超过了 Mythos,不过这只是拼图的一部分》 https://mp.weixin.qq.com/s/BzU7g-2iG7d6h4ViwMhxyg 部分内容摘录: > 在看到 Daniel Stenberg 那篇关于 Mythos 的文章之后,我们用阿图因 AI 对 curl 项目进行分析,发现了一个新漏洞(CVE-2026-9079)。这个漏洞被 curl 官方定级为中危。2026 年 6 月 24 日,curl 在 8.21.0 版本中修复了我们发现的这个漏洞。 > 也就是说,我们的阿图因 AI 发现了一个 Mythos 没有发现的漏洞。 > 那么,能否说阿图因 AI 比 Mythos 更强呢? > 这个问题无法简单地用“能”或者“不能”来回答。这不仅是因为我们访问不了 Mythos,无法进行直接的对比,更重要的是,阿图因 AI 是一个 Agent,而 Mythos 是一个模型。阿图因 AI 是为漏洞挖掘等特定任务而设计的,对这些特定任务,阿图因 AI 也许表现地更好,但对设计目标之外的任务,哪怕是数据恢复、恶意软件分析之类的安全任务,大概还是 Mythos 比较强。

    Post summary

    A new vulnerability, CVE-2026-9079, was identified by Atun AI in the curl project and was addressed in curl 8.21.0, showcasing the AI’s ability to uncover issues overlooked by other tools.

    2201291222.9K
    246.4K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - curl / libcurl Proxy Credentials Not Cleared on Reset (CVE-2026-9079) libcurl had a flaw where instructing it to clear proxy authentication credentials didn't actually clear them. The old proxy credentials were left in place and could be reused on subsequent transfers on the same handle - transfers that should never have known or used them. This is a credential-leak / logic bug (CWE-522), not remote code execution, and it requires an application that reuses a curl handle and relies on clearing proxy credentials between transfers. 👉Upgrade to curl/libcurl 8.21.0 (affects 8.8.0–8.20.0).

    Post summary

    The advisory highlights a credential‑leak bug in libcurl that fails to clear proxy authentication data, and recommends users upgrade to libcurl 8.21.0 to remediate the issue.

    0000070
    243 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more