The curl project released curl/libcurl 8.20.0 with fixes for several disclosed vulnerabilities that could leak credentials, cookies, or authenticated session state across requests, redirects, proxies, and reused connections. The most broadly exposed issue, CVE-2026-6253, allows proxy credentials to be forwarded to a different proxy during cross-scheme redirects when separate proxies are configured; it affects curl and libcurl from 7.14.1 through 8.19.0. curl also fixed CVE-2026-5545, where HTTP(S) connections authenticated with Negotiate could be wrongly reused for a different user, potentially sending requests over a connection still authenticated as the first user; that flaw affects versions 7.10.6 through 8.19.0 and also impacts the command-line tool.
Additional flaws primarily affect libcurl handle and connection reuse. CVE-2026-7168 can leak Digest proxy authentication state when the same handle is reused across different HTTP proxies, CVE-2026-6429 can expose .netrc credentials during HTTP redirects over a reused proxied connection, and CVE-2026-6276 can send cookies for one host to another after reuse of an easy handle with a removed custom Host: header. The affected ranges span from 7.12.0 to 8.19.0 depending on the bug, and curl advised users to upgrade to 8.20.0, apply the published patches, or avoid risky patterns such as proxy credential use, custom Host: headers, .netrc with proxied cleartext HTTP, HTTP Negotiate, and handle reuse when switching proxies.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
On April 29, 2026, curl publicly disclosed CVE-2026-5545, CVE-2026-6253, CVE-2026-6276, CVE-2026-6429, and CVE-2026-7168. The project said these issues were fixed in curl/libcurl 8.20.0 and advised users to upgrade or apply patches.
A GitHub commit dated April 27, 2026 added changes and a test around clearing proxy authentication properties when switching proxies. The commit aligns with the later disclosure of CVE-2026-7168.
curl said CVE-2026-7168 was reported on April 27, 2026. The bug concerned leakage of Digest proxy authentication state when reusing a libcurl handle across different proxies.
curl stated that CVE-2026-5545 was coordinated with distros@openwall on April 23, 2026 ahead of public disclosure. This reflects the project's pre-release vulnerability coordination process.
A GitHub commit dated April 14, 2026 introduced helper functions to reset user and proxy credentials before transfers. The change modified how libcurl restores configured credentials into transfer state.
curl said the vulnerability later assigned CVE-2026-5545 was reported on April 1, 2026. The flaw involved incorrect reuse of Negotiate-authenticated HTTP(S) connections across different credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcecurl.se
Open sourcecurl.se
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.