← Back to CVE List
Vulnerability Intelligence Report
Negotiate ambient user conn reuse

CVE-2026-19931

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:1.16%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-488 ↗Exposure of Data Element to Wrong Session

Affected Products & Versions

Vendor Product Affected Versions
curl curl 7.64.1 < 8.14.2 (affected), 8.15.0 < 8.16.1 (affected), 8.17.0 < 8.20.1 (affected), 8.21.0 < 8.22.0 (affected)
curl curl 6c6035532383e300c712e4c1cd9fdd749ed5cf59 < 7103a93b05bc69ea98ed9d05d02fa9eeba533f2f (affected)
curl curl 8.21.0 (affected), 8.20.0 (affected), 8.19.0 (affected), 8.18.0 (affected), 8.17.0 (affected), 8.16.0 (affected), 8.15.0 (affected), 8.14.1 (affected), 8.14.0 (affected), 8.13.0 (affected), 8.12.1 (affected), 8.12.0 (affected), 8.11.1 (affected), 8.11.0 (affected), 8.10.1 (affected), 8.10.0 (affected), 8.9.1 (affected), 8.9.0 (affected), 8.8.0 (affected), 8.7.1 (affected), 8.7.0 (affected), 8.6.0 (affected), 8.5.0 (affected), 8.4.0 (affected), 8.3.0 (affected), 8.2.1 (affected), 8.2.0 (affected), 8.1.2 (affected), 8.1.1 (affected), 8.1.0 (affected), 8.0.1 (affected), 8.0.0 (affected), 7.88.1 (affected), 7.88.0 (affected), 7.87.0 (affected), 7.86.0 (affected), 7.85.0 (affected), 7.84.0 (affected), 7.83.1 (affected), 7.83.0 (affected), 7.82.0 (affected), 7.81.0 (affected), 7.80.0 (affected), 7.79.1 (affected), 7.79.0 (affected), 7.78.0 (affected), 7.77.0 (affected), 7.76.1 (affected), 7.76.0 (affected), 7.75.0 (affected), 7.74.0 (affected), 7.73.0 (affected), 7.72.0 (affected), 7.71.1 (affected), 7.71.0 (affected), 7.70.0 (affected), 7.69.1 (affected), 7.69.0 (affected), 7.68.0 (affected), 7.67.0 (affected), 7.66.0 (affected), 7.65.3 (affected), 7.65.2 (affected), 7.65.1 (affected), 7.65.0 (affected), 7.64.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.162%

Identity & Timeline

StatusPUBLISHED
Assigning Authoritycurl · Open Source · Sweden
Reserved2026-08-15T10:35:02
Published2026-09-06T17:47:43
Last Updated2026-09-15T06:02:51

LINK COPIED TO CLIPBOARD