Impact
According to the updated description, libcurl does not clear proxy authentication credentials when instructed, leaving stale credentials in memory. These stale credentials can be reused by subsequent transfers that should not have access to them, potentially exposing sensitive authentication information.
Affected Systems
The issue affects the libcurl library distributed as curl. No specific version numbers are listed in the CNA data, so any installation that invokes the proxy authentication clearing routine in libcurl and has not applied a fix may be vulnerable. Applications that embed libcurl and rely on proxy credentials are therefore exposed.
Risk and Exploitability
The high CVSS score signals severe potential impact, while the EPSS score of <1% indicates that exploitation is considered unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. An attacker who can influence the use of libcurl could trigger the reuse of stale proxy credentials, allowing them to impersonate the original client or gain unauthorized access to upstream services. Although the flaw does not permit arbitrary code execution, it can compromise the confidentiality of proxy credentials and enable unauthorized upstream service access.
OpenCVE Enrichment
Ubuntu USN