Description

curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.

INFO

Published Date :

2026-03-11T10:09:21.418Z

Last Modified :

2026-03-11T15:48:41.725Z

Source :

curl
AFFECTED PRODUCTS

The following products are affected by CVE-2026-3784 vulnerability.

Vendors Products
Curl
  • Curl
Haxx
  • Curl

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact