Broadcom has completed an assessment of the impact of CVE-2026-8924 (libcurl 7.12.0 < 8.21.0 Cross-Proxy Digest Auth State Leak) on the DLP product suite. This article details the impact across DLP Enforce Servers, Endpoint Agents, and other infrastructure components.
Data Loss Prevention
Engineering has confirmed that the DLP product suite, including the Enforce Server, Detection Servers and Endpoint Agent, does not use the curl cookie parsing logic affected by CVE-2026-8924. Consequently, DLP infrastructure is not impacted by this vulnerability.