CVE-2026-8927
CVE Details
Visit the official vulnerability details page for CVE-2026-8927 to learn more.
Initial Publication
07/03/2026
Last Update
07/07/2026
Third Party Dependency
curl-minimal
NIST CVE Summary
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
CVE Severity
Our Official Summary
Investigation is ongoing to determine how this vulnerability affects our products.
Status
Analyzed
Affected Products & Versions
| Version | PaletteAI | PaletteAI VerteX |
|---|---|---|
| 1.2.1 | ⚠️ Impacted | ⚠️ Impacted |
Revision History
No revisions available.