IM
IronMonkey Threat Research

CVE-2026-3784 MEDIUM

Published: 2026-03-11 | Last Modified: 2026-06-02 | Status: Modified

Description

curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.

Additional Descriptions (1)

curl reutilizaría erróneamente una conexión proxy HTTP existente haciendo CONNECT a un servidor, incluso si la nueva solicitud utiliza credenciales diferentes para el proxy HTTP. El comportamiento adecuado es crear o usar una conexión separada.

CVSS Metrics

Base Score: 6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactLOW
Integrity ImpactLOW
Availability ImpactNONE

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Type: Secondary

Exploitability Score: 3.9

Impact Score: 2.5

Weaknesses

Source Type Description
134c704f-9b21-4f2e-91b3-4a467353bcc0 Secondary
en CWE-305

Affected Products

Vendor Product Version Update Type
haxx curl * <built-in method update of dict object at 0x7f7600be5300> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*

References

Notification
Message here