In plain language
What this advisory means
A vulnerability in some Microsoft-distributed curl versions for Azure Linux and CBL-Mariner allows incorrect reuse of proxy connections with credentials. This may expose sensitive authentication data. Users should review Microsoft's security guide to see if their systems are affected and update accordingly.
Technical explanation
How the issue affects the environment
Microsoft identified a vulnerability (CVE-2026-3784) involving wrong proxy connection reuse with credentials in curl versions 8.11.1-5 on Azure Linux 3.0 and 8.8.0-8 on CBL-Mariner 2.0. The issue lies in improper handling of proxy connection reuse, where credentials might be mistakenly reused across sessions, potentially leading to credential leakage. Fixed versions include curl 8.11.1-6 and 8.8.0-9 on the respective platforms. Users must update to these versions to correct the flaw.
Operational impact
Why teams should care
This flaw can lead to unauthorized disclosure of proxy authentication credentials, risking exposure of sensitive information and potential unauthorized access to network resources. Organizations relying on affected curl versions on Azure Linux or CBL-Mariner could face increased security risks if unpatched.
Immediate action
Users should upgrade affected curl versions on Azure Linux 3.0 and CBL-Mariner 2.0 to the fixed versions 8.11.1-6 and 8.8.0-9 respectively. Refer to the Microsoft Security Update Guide and Azure Linux upgrade tutorials for detailed instructions.
Affected and fixed releases
Temporary risk reduction
No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.
Evidence and validation checklist
- Microsoft Security Response Center advisory CVE-2026-3784
- Microsoft Security Update Guide reference
- Version and fix information matching curl on Azure Linux and CBL-Mariner platforms
- CVSS score of 6.5 indicating moderate severity
Authoritative reference
Microsoft Security Response Center
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
