Back to search
CVE-2026-7168
Published: May 13, 2026
Modified: May 13, 2026
PUBLISHED
Description
Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for `proxyA`, to `proxyB`.
| Vendor | Product | Versions |
|---|---|---|
curl | curl | affected 8.19.0 - <= 8.19.0affected 8.18.0 - <= 8.18.0affected 8.17.0 - <= 8.17.0affected 8.16.0 - <= 8.16.0affected 8.15.0 - <= 8.15.0+160 more versions |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now