CVE List

CVE-2026-3784

Moderate 6.5

curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.

Published March 11, 2026.

Affected software

Get alerts for Haxx Curl

Reference links