VDB

CVE-2026-19931

CVE-2026-19931 PUBLISHED CVSS 9.8 CRITICAL

Reported by curl · Published September 6, 2026

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

Risk Scores

CVSS 3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
curlcurl7.64.1, 8.15.0, 8.17.0
curlcurl6c6035532383e300c712e4c1cd9fdd749ed5cf59
curlcurl8.21.0, 8.20.0, 8.19.0
curlcurl7.64.1, 7.80.0, 7.79.1
chainguardcurl0
wolficurl0, 0, 0
alpinecurl0, 0, 0

Timeline

  • CVE Published
  • Sep 3, 2026 PoC Published
  • Sep 7, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›