
Information Disclosure (CWE-200)CVSS 5.5€0
CVE-2026-9079: stale proxy password leak
keen4n
Disclosed on HackerOne · June 24, 2026
Publicly disclosed report · by keen4n
View original on HackerOneProduct
Product name: curl / libcurl
Product link: https://github.com/curl/curl
Suggested CWE: CWE-226: Sensitive Information in Resource Not Removed Before Reuse (https://cwe.mitre.org/data/definitions/226.html); alternative CWE-200: Exposure of Sensitive Information to an Unauthorized Actor (https://cwe.mitre.org/data/definitions/200.html)
Affected versions: 8.8.0 <= libcurl <= 8.20.0 are confirmed affected. curl/libcurl 8.21.0-DEV, commit b2476a07128fc1e83a0b322fe6eb9dfa761db53d, is also affected.