Security Advisory Desk
mediumQCS priority 76/100Microsoft

CVE-2026-3784: wrong proxy connection reuse with credentials

A vulnerability in some Microsoft-distributed curl versions for Azure Linux and CBL-Mariner allows incorrect reuse of proxy connections with credentials. This may expose sensitive authentication data. Users should review Microsoft's security guide to see if their systems are affected and update accordingly.

QCS published 4/10/2026, 8:51:43 am ISTVendor disclosure 10/3/2026, 12:30:00 pm ISTVerified 4/10/2026, 8:51:43 am ISTRevision 1

In plain language

What this advisory means

A vulnerability in some Microsoft-distributed curl versions for Azure Linux and CBL-Mariner allows incorrect reuse of proxy connections with credentials. This may expose sensitive authentication data. Users should review Microsoft's security guide to see if their systems are affected and update accordingly.

Technical explanation

How the issue affects the environment

Microsoft identified a vulnerability (CVE-2026-3784) involving wrong proxy connection reuse with credentials in curl versions 8.11.1-5 on Azure Linux 3.0 and 8.8.0-8 on CBL-Mariner 2.0. The issue lies in improper handling of proxy connection reuse, where credentials might be mistakenly reused across sessions, potentially leading to credential leakage. Fixed versions include curl 8.11.1-6 and 8.8.0-9 on the respective platforms. Users must update to these versions to correct the flaw.

Operational impact

Why teams should care

This flaw can lead to unauthorized disclosure of proxy authentication credentials, risking exposure of sensitive information and potential unauthorized access to network resources. Organizations relying on affected curl versions on Azure Linux or CBL-Mariner could face increased security risks if unpatched.

Immediate action

Users should upgrade affected curl versions on Azure Linux 3.0 and CBL-Mariner 2.0 to the fixed versions 8.11.1-6 and 8.8.0-9 respectively. Refer to the Microsoft Security Update Guide and Azure Linux upgrade tutorials for detailed instructions.

Affected and fixed releases

Affected versions8.11.1-5, 8.8.0-8
Fixed versions8.11.1-6, 8.8.0-9

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • Microsoft Security Response Center advisory CVE-2026-3784
  • Microsoft Security Update Guide reference
  • Version and fix information matching curl on Azure Linux and CBL-Mariner platforms
  • CVSS score of 6.5 indicating moderate severity

Authoritative reference

Microsoft Security Response Center

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source