Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-79679.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-79679
Upstream
Published
2026-03-11T11:16:00Z
Modified
2026-08-31T05:26:27Z
Summary
CVE-2026-3784 affecting package curl for versions less than 8.11.1-6
Details

curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.

References

Affected packages

Azure Linux:3 / curl

Package

Name
curl
Purl
pkg:rpm/azure-linux/curl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.11.1-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-79679.json"