VDB
CVE-2026-19931
CVE-2026-19931
PUBLISHED
CVSS 9.8 CRITICAL
Reported by curl · Published September 6, 2026
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
Risk Scores
CVSS 3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| curl | curl | 7.64.1, 8.15.0, 8.17.0 |
| curl | curl | 6c6035532383e300c712e4c1cd9fdd749ed5cf59 |
| curl | curl | 8.21.0, 8.20.0, 8.19.0 |
| curl | curl | 7.64.1, 7.80.0, 7.79.1 |
| chainguard | curl | 0 |
| wolfi | curl | 0, 0, 0 |
| alpine | curl | 0, 0, 0 |
Timeline
- CVE Published
- Sep 3, 2026 PoC Published
- Sep 7, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score