CVE-2026-3784
curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.41%
- CWE
- CWE-305
- Published
- 2026-03-11
- Last modified
- 2026-09-15
Affected products
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
Weakness type
Related vulnerabilities
- CVE-2025-31161 — CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
- CVE-2023-34124 — The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio
- CVE-2021-26102 — A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remot
- CVE-2023-0777 — Authentication Bypass by Primary Weakness in modoboa/modoboa
- CVE-2024-50478 — WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerability
- CVE-2022-2651 — Authentication Bypass by Primary Weakness in bookwyrm-social/bookwyrm
- CVE-2026-81578 — PaperCut MF/NG: Authentication Bypass
- CVE-2026-25555 — OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header