When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.12.0, < 8.21.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
>= 7.12.0, <= 7.12.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.12.1, <= 7.12.1CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.12.2, <= 7.12.2CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.12.3, <= 7.12.3CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.