---
schema_version: '1.0'
id: security-20260709-7b9856
url: https://osv.dev/vulnerability/CVE-2026-9079
url_hash: 7b9856cac7b8431212f5363b04bcb75f3d914a1a8ba87367f792eccaa19d770d
canonical_url: https://osv.dev/vulnerability/CVE-2026-9079
source: osv:nvd
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-9079
- severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- https://github.com/curl/curl
- GIT
lang: en
published_at: '2026-07-03T06:16:51Z'
fetched_at: '2026-07-09T15:38:26Z'
updated_at: '2026-07-09T15:38:50Z'
status: published
content_hash: 65a1283c9738363faceb79e30c6e426e6d334ef81c330841682c1f702998c82d
license_note: full
summary: stale proxy password leak
summary_source: rss
summary_en: stale proxy password leak
entities:
- name: CVE-2022-26925
  type: event
- name: GitHub
  type: organization
- name: earlyappleleaks
  type: person
key_facts: []
related: []
related_auto:
- name: GitLost
  type: concept
  weight: 4.0
- name: Windowsローカルセキュリティ認証機関(LSA
  type: location
  weight: 1.0
- name: AI Agent
  type: concept
  weight: 1.0
- name: Hy3
  type: artifact
  weight: 1.0
- name: OpenClaw
  type: artifact
  weight: 1.0
title: 'CVE-2026-9079: stale proxy password leak'
---

# CVE-2026-9079: stale proxy password leak

## TL;DR
stale proxy password leak

## Key Points
- cve / CVE-2026-9079 / severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H / https://github.com/curl/curl / GIT

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
**Advisory:** CVE-2026-9079

**Affected (your watchlist):**
- `GIT:https://github.com/curl/curl` curl-8_9_1 → no fixed version listed [mac]

**Details:**
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.

**References:**
- https://curl.se/docs/CVE-2026-9079.html
- https://curl.se/docs/CVE-2026-9079.json
- https://hackerone.com/reports/3750295
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9079.json
- https://nvd.nist.gov/vuln/detail/CVE-2026-9079

_Data: OSV.dev (upstream: nvd) — https://osv.dev/vulnerability/CVE-2026-9079_

## Source
元記事: [CVE-2026-9079: stale proxy password leak](https://osv.dev/vulnerability/CVE-2026-9079) — published 2026-07-03T06:16:51Z
