CVE-2026-3784

Publication date 11 March 2026

Last updated 11 March 2026


Ubuntu priority

Description

From the Ubuntu Security Team

curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.

Why is this CVE low priority?

Upstream defined it as low

Learn more about Ubuntu priority

Status

Package Ubuntu Release Status
curl 25.10 questing
Fixed 8.14.1-2ubuntu1.2
24.04 LTS noble
Fixed 8.5.0-2ubuntu10.8
22.04 LTS jammy
Fixed 7.81.0-1ubuntu1.23
20.04 LTS focal
Vulnerable
18.04 LTS bionic
Vulnerable
16.04 LTS xenial
Vulnerable
14.04 LTS trusty
Vulnerable

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
curl

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities