# CVE-2026-9079

## Summary

- **CVE ID:** CVE-2026-9079
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-522
- **Published:** Jul 3, 2026
- **Last Modified:** Sep 17, 2026

## Description

libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.

## Affected Products

- curl — curl (8.20.0)
- curl — curl (8.19.0)
- curl — curl (8.18.0)
- curl — curl (8.17.0)
- curl — curl (8.16.0)
- curl — curl (8.15.0)
- curl — curl (8.14.1)
- curl — curl (8.14.0)
- curl — curl (8.13.0)
- curl — curl (8.12.1)
- curl — curl (8.12.0)
- curl — curl (8.11.1)
- curl — curl (8.11.0)
- curl — curl (8.10.1)
- curl — curl (8.10.0)
- curl — curl (8.9.1)
- curl — curl (8.9.0)
- curl — curl (8.8.0)
- curl — curl (d5e83eb745762f48d8fafadc5df5dd3ae8d8941e)

## References

- [CNA](https://curl.se/docs/CVE-2026-9079.json)
- [CNA](https://curl.se/docs/CVE-2026-9079.html)
- [CNA](https://hackerone.com/reports/3750295)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.58%
- **EPSS Percentile:** 46.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._