یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
نامشخص EPSS 0.6% اولویت 10/100

CVE-2026-9079— CVE-2026-9079: stale proxy password leak

USN-8487-1 fixed vulnerabilities in curl. Unfortunately that update contained an incomplete fix for CVE-2026-8927. This update fixes the problem. Original advisory details: Andrew Nesbitt discovered that curl could reuse an existing live connection during STARTTLS-based connection upgrades even when the TLS configuration did not match. A remote attacker could possibly use this issue to cause curl to use an unintended TLS configuration. (CVE-2026-8286) Muhamad Arga Reksapati discovered that curl incorrectly reused connections for Negotiate-authenticated requests when different services were involved. A remote attacker could possibly use this issue to access resources authenticated for another service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu…

انتشار: 2026-06-24 00:00 آخرین مشاهده داده: 2026-09-29 10:40 2 منبع · 2 رسمیاعتماد خوب · 61/100
اولویت VulnWatch 10/100 ترکیب سیگنال‌های ریسک موجود
CVSS / EPSS — / 0.6% شدت فنی / احتمال بهره‌برداری
کیفیت داده 51/100 نیازمند توجه · اعتماد خوب
تازگی در حال قدیمی‌شدن به‌روز در ۳۰ روز · 2 منبع
راهنمای اقدام

الان چه کاری باید انجام شود؟

پایش و ارزیابی
EPSS 0.6%سیگنال EPSS پایین‌تر است؛ سایر شاخص‌ها را نیز در تصمیم لحاظ کنید.
کیفیت داده 51/100نیازمند توجه · 2 منبع؛ پیش از تغییر Production منبع اصلی را بررسی کنید.
راهکارراهکار ساختاریافته هنوز ثبت نشده است؛ مراجع اصلی را بررسی کنید.
رفتن به راهکار این راهنمای اقدام، RiskScorer را تغییر نمی‌دهد و جایگزین ارزیابی محیط شما نیست.
اولویت عملیاتی 2.5

چرا این مورد باید بررسی شود؟

این امتیاز مستقل از RiskScorer است و برای مرتب‌سازی اقدام‌های عملیاتی استفاده می‌شود.

Priority14
تغییر مهم: تغییر نسخه‌های درگیر
01

خلاصه آسیب‌پذیری

USN-8487-1 fixed vulnerabilities in curl. Unfortunately that update contained an incomplete fix for CVE-2026-8927. This update fixes the problem. Original advisory details: Andrew Nesbitt discovered that curl could reuse an existing live connection during STARTTLS-based connection upgrades even when the TLS configuration did not match. A remote attacker could possibly use this issue to cause curl to use an unintended TLS configuration. (CVE-2026-8286) Muhamad Arga Reksapati discovered that curl incorrectly reused connections for Negotiate-authenticated requests when different services were involved. A remote attacker could possibly use this issue to access resources authenticated for another service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu…
02

توضیحات کامل

USN-8487-1 fixed vulnerabilities in curl. Unfortunately that update contained an incomplete fix for CVE-2026-8927. This update fixes the problem. Original advisory details: Andrew Nesbitt discovered that curl could reuse an existing live connection during STARTTLS-based connection upgrades even when the TLS configuration did not match. A remote attacker could possibly use this issue to cause curl to use an unintended TLS configuration. (CVE-2026-8286) Muhamad Arga Reksapati discovered that curl incorrectly reused connections for Negotiate-authenticated requests when different services were involved. A remote attacker could possibly use this issue to access resources authenticated for another service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458) It was discovered that curl incorrectly handled cookie parsing in certain circumstances. A remote attacker could possibly use this issue to set cookies that would be transmitted to unrelated third-party domains. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8924) Joshua Rogers discovered that curl could double-free a GSASL context when handling SASL authentication. A remote attacker could possibly use this issue to cause a denial of service, or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8925) Joshua Rogers discovered that curl could select the wrong password from a .netrc file when a username was specified in the URL without a password. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-8926) Ady Elouej discovered that curl did not clear proxy authentication state between requests when reusing a handle with environment-variable proxy configuration. A remote attacker could possibly use this issue to obtain sensitive credentials. (CVE-2026-8927) Guannan Wang, Zhanpeng Liu, Jiashuo Liang, and Guancheng Li discovered that curl did not properly clear proxy authentication credentials when instructed to do so. A remote attacker could possibly use this issue to obtain sensitive credentials. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-9079) Joshua Rogers discovered that curl contained a use-after-free when curl_easy_pause() was called within the event-based socket callback. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-9080) Eunsoo Kim discovered that curl could send early data on a resumed TLS session before enforcing certificate verification failure. A machine-in- the-middle attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-9545) Joshua Rogers discovered that curl did not properly reject host key type mismatches when using the SSH key callback for SCP and SFTP transfers. A machine-in-the-middle attacker could possibly use this issue to impersonate a trusted server. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-9547)
✓

راهکار پیشنهادی برای رفع

اقدام پیشنهادی
در اطلاعات دریافت‌شده هنوز راهکار مشخصی ثبت نشده است.
در اطلاعات دریافت‌شده دستور اجرایی مشخصی پیدا نشد. برای بررسی کامل راهکار، منبع اصلی را باز کنید.
↺

تاریخچه تغییرات معنادار

فقط تغییرات امنیتی مهم مثل KEV، افزایش شدت/CVSS/EPSS، نسخه‌های درگیر و راهکار ثبت می‌شوند.
تغییر نسخه‌های درگیر

دامنه نسخه‌های درگیر یا اصلاح‌شده تغییر کرد.

versions
◎

اعتماد، تازگی و پوشش داده

این شاخص عملیاتی از پوشش منابع، کامل‌بودن رکورد، تازگی داده و اختلاف بین منابع ساخته می‌شود و تضمین صحت نیست.
61/100
اعتماد خوب اعتماد داده 51/100 نیازمند توجه در حال قدیمی‌شدن وضعیت تازگی به‌روز در ۳۰ روز تازگی مشاهده 63/100 کامل‌بودن · ناقص 79/100 پوشش منابع 2 منبع مرتبط 2 رسمی · 2 سطح ۱ 2 اختلاف بین منابع 3 خلأ کیفیت
اختلاف بین منابع دیده شد

اختلاف‌ها مخفی نمی‌شوند و در شاخص اعتماد نیز اثر کاهشی دارند. پیش از تصمیم عملیاتی، مقدار هر منبع را بررسی کنید.

محصول
Canonical / Ubuntucurl / curl/libcurl
تاریخ انتشار
2026-09-282026-06-24
Ubuntu Security Notices رسمی
CVSS
—
شدت
unknown
محصول
Canonical / Ubuntu
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
2026-09-28
curl CVEs رسمی
CVSS
—
شدت
unknown
محصول
curl / curl/libcurl
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
2026-06-24
curl CVEs رسمی
CVSS
—
شدت
unknown
محصول
curl / curl/libcurl
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
2026-06-24
⌁

منبع هر داده

برای فیلدهای اصلی می‌توانید ببینید هر مقدار از کدام منبع ثبت شده است. اختلاف بین منابع پنهان نمی‌شود.
توضیحات 3 منبع
Ubuntu Security Noticesرسمی
USN-8487-1 fixed vulnerabilities in curl. Unfortunately that update contained an incomplete fix for CVE-2026-8927. This update fixes the problem. Original advisory details: Andrew Nesbitt discovered that curl could reuse an existing live connection during STARTTLS-based connection upgrades even when the TLS configuration did not match. A remote attacker could possibly use this issue to cause cur...
منبع ↗
curl CVEsرسمی
196 M lib CVE-2026-9079: stale proxy password leak 2026-06-24 8.8.0 8.20.0
منبع ↗
curl CVEsرسمی
196 M lib CVE-2026-9079: stale proxy password leak 2026-06-24 8.8.0 8.20.0
منبع ↗
شدت 3 منبع
Ubuntu Security Noticesرسمی
unknown
منبع ↗
curl CVEsرسمی
unknown
منبع ↗
curl CVEsرسمی
unknown
منبع ↗
خلاصه 3 منبع
Ubuntu Security Noticesرسمی
USN-8487-1 fixed vulnerabilities in curl. Unfortunately that update contained an incomplete fix for CVE-2026-8927. This update fixes the problem. Original advisory details: Andrew Nesbitt discovered that curl could reuse an existing live connection during STARTTLS-based connection upgrades even when the TLS configuration did not match. A remote attacker could possibly use this issue to cause cur...
منبع ↗
curl CVEsرسمی
196 M lib CVE-2026-9079: stale proxy password leak 2026-06-24 8.8.0 8.20.0
منبع ↗
curl CVEsرسمی
196 M lib CVE-2026-9079: stale proxy password leak 2026-06-24 8.8.0 8.20.0
منبع ↗
عنوان 3 منبع
Ubuntu Security Noticesرسمی
USN-8487-2: curl regression
منبع ↗
curl CVEsرسمی
CVE-2026-9079: stale proxy password leak
منبع ↗
curl CVEsرسمی
8.8.0
منبع ↗
↗