PT-2026-35898 · Git · Curl

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-7168

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Successfully using libcurl to do a transfer over a specific HTTP proxy (proxyA) with Digest authentication and then changing the proxy host to a second one (proxyB) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the Proxy-Authorization: header field meant for proxyA, to proxyB.

Weakness Enumeration

Related Identifiers

CVE-2026-7168

Affected Products

Curl