---
schema_version: '1.0'
id: security-20260705-f5d43e
url: https://osv.dev/vulnerability/CURL-CVE-2026-9079
url_hash: f5d43e7a314b22bc14c9e09e49da405b8647885ef11155416063fbe30708fb2a
canonical_url: https://osv.dev/vulnerability/CURL-CVE-2026-9079
source: osv:osv
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-9079
- CURL-CVE-2026-9079
- severity:Medium
- https://github.com/curl/curl
- GIT
lang: en
published_at: '2026-06-24T08:00:00Z'
fetched_at: '2026-07-05T15:34:34Z'
updated_at: '2026-07-05T15:37:47Z'
status: published
content_hash: 339b242c87eb1afa5ac25fbdd6cbabaa19df43b46a42976b75eb9020461cced9
license_note: full
summary: stale proxy password leak
summary_source: rss
summary_en: stale proxy password leak
entities:
- name: GitHub
  type: organization
- name: earlyappleleaks
  type: person
key_facts: []
related: []
related_auto:
- name: Anonymous
  type: organization
  weight: 1.0
- name: AirPods
  type: artifact
  weight: 1.0
- name: Claude Code
  type: artifact
  weight: 1.0
- name: セッション漏洩
  type: event
  weight: 1.0
- name: local-llm
  type: content
  weight: 1.0
title: 'CVE-2026-9079: stale proxy password leak'
---

# CVE-2026-9079: stale proxy password leak

## TL;DR
stale proxy password leak

## Key Points
- cve / CVE-2026-9079 / CURL-CVE-2026-9079 / severity:Medium / https://github.com/curl/curl / GIT

## Details
**Severity:** Medium
**Advisory:** CURL-CVE-2026-9079 (CVE-2026-9079)

**Affected (your watchlist):**
- `GIT:https://github.com/curl/curl` curl-8_9_1 → no fixed version listed [mac]

**Details:**
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.

_Data: OSV.dev (upstream: osv) — https://osv.dev/vulnerability/CURL-CVE-2026-9079_

## Source
元記事: [CVE-2026-9079: stale proxy password leak](https://osv.dev/vulnerability/CURL-CVE-2026-9079) — published 2026-06-24T08:00:00Z
