curl might erroneously pass on credentials for a first proxy to a second proxy.
This can happen when the following conditions are true:
http://), curl is asked to follow
a redirect to a URL using another scheme (say https://), accessed using a
second, different, proxy{
"cna_assigner": "curl",
"cwe_ids": [
"CWE-522"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6253.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "7.14.1"
},
{
"fixed": "8.14.2"
},
{
"introduced": "8.15.0"
},
{
"fixed": "8.16.1"
},
{
"introduced": "3b60bb725913ce7339aefef0a14b12df4c24db60"
},
{
"fixed": "188c2f166a20fa97c2325b2da7d0e5cecc13725f"
}
],
"source": "AFFECTED_FIELD"
}
]
}