https://seclists.org/oss-sec/2026/q2/272: [ADVISORY] curl: CVE-2026-7168: cross-proxy Digest auth state leak
Published Apr 29, 2026
·Updated
Affected Software
1 affected component
curl libcurl>=7.12.0<=8.19.0
Frequently Asked Questions
1
What is the severity of CVE-2026-7168?
CVE-2026-7168 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2026-7168?
To mitigate CVE-2026-7168, upgrade to the latest version of curl or apply the provided patches.
3
What kind of information can be leaked due to CVE-2026-7168?
CVE-2026-7168 can leak sensitive Digest authentication state information between different proxies.
4
Which versions of curl are affected by CVE-2026-7168?
CVE-2026-7168 affects older versions of curl that utilize Digest authentication over proxies.
5
Is there a workaround for CVE-2026-7168?
Currently, the best workaround for CVE-2026-7168 is to avoid using Digest authentication with vulnerable proxy configurations.