CVE-2026-3784: cURL vulnerability analysis and mitigation
curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a
server, even if the new request uses different credentials for the HTTP proxy.
The proper behavior is to create or use a separate connection.
Source: NVD
Related cURL vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-3805
HIGH
7.5
cURL
rust-std-static-x86_64-unknown-none
No
Yes
Mar 11, 2026
CVE-2026-3784
MEDIUM
6.5
cURL
curl-minimal
No
Yes
Mar 11, 2026
CVE-2026-1965
MEDIUM
6.5
cURL
clippy
No
Yes
Mar 11, 2026
CVE-2026-3783
MEDIUM
5.3
cURL
rust-std-static-wasm32-wasip1
No
Yes
Mar 11, 2026
CVE-2025-11563
MEDIUM
4.6
cURL
libcurl4-32bit
No
Yes
Feb 25, 2026
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.