CVE-2026-7168EPSS p46.4%
CVE-2026-7168CVE-2026-7168
haxx / curl
Description
Successfully using libcurl to do a transfer over a specific HTTP proxy
(`proxyA`) with **Digest** authentication and then changing the proxy host to
a second one (`proxyB`) for a second transfer, reusing the same handle, makes
libcurl wrongly pass on the `Proxy-Authorization:` header field meant for
`proxyA`, to `proxyB`.
Scoring
| CVSS | 5.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.59% probability of exploitation · percentile 46.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-15 |