Sploitus

CVE-2026-8927

No indexed exploits for CVE-2026-8927 yet

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.

Affected products
Ibm Aix, Linuxmint, Ubuntu, Libcurl
Haxx Curl
< 8.21.0
CVSS 3.1
9.1 CRITICAL
EPSS
0.4% (36th percentile)
Weakness
CWE-294
NVD status
Analyzed
Published
2026-07-03
CVE-2026-8927 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-8927 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-8927 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.