CVE Database
/

CVE-2026-3784

Back to search

CVE-2026-3784

Published: Mar 11, 2026

Modified: Jun 2, 2026

PUBLISHED

Description

curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.

VendorProductVersions

curl

curl

affected
8.18.0 - <= 8.18.0
affected
8.17.0 - <= 8.17.0
affected
8.16.0 - <= 8.16.0
affected
8.15.0 - <= 8.15.0
affected
8.14.1 - <= 8.14.1

+186 more versions

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now