CVE•Published 2026-05-13•Modified 2026-05-14•0 articles on news•5 live references•NVD data
CVE-2026-7168Haxx · Curl
Vulnerability data via NVD (ingested)
CVSS v3.1
5.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS percentile
—
Weaknesses (CWE)
Description
Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for `proxyA`, to `proxyB`.
Timeline
Published 2026-05-13
Modified 2026-05-14
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-7168Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Haxx Curl"All exposed Haxx Curl instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Curl"HTTP body or banner mentions "Curl" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-7168Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-7168Censys host search filtered to this CVE id.
grep.app
CVE-2026-7168Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-7168GitHub code search for direct mentions.
Google dork
"CVE-2026-7168" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (4)
CVE-2026-71684 repos
hiifong/starListPython
Export your star's repository list
mr4tt/zotbotPython
links!!!! lots of links. uploading my zotero library to github
Steel-SecAdv-LLC/Mercury-AgentPython
Mercury Agent ♱ - Is a neuro-symbolic autonomous AI prototype, integrating machine learning-based anomaly detection, multi-domain operations, and ethical alignment protocols. Desig…
AncientMystic/HomeLabunknown
HomeLab CheatSheet & AwesomeList
We haven't classified any articles referencing CVE-2026-7168 yet. The external references above still apply.