Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91791.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-91791
Upstream
Published
2026-07-03T07:16:25Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-9079 affecting package curl for versions less than 8.11.1-10
Details

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

References

Affected packages

Azure Linux:3 / curl

Package

Name
curl
Purl
pkg:rpm/azure-linux/curl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.11.1-10

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91791.json"