View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2026-9079 severity important: SUSE including 24 source package names (curl, curl-8.14.1-150400.5.86.1, …), 98 product×package rows across 30 product lines (Container suse/sles/16.0/toolbox, SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS, … (30 product lines)): First Fixed 82, Known Not Affected 14, Fixed 2.
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.