Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-19931

Опубликовано: 06 сент. 2026
Источник: debian
EPSS Низкий

Описание

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed8.22.0~rc2-1package
curlno-dsatrixiepackage
curlpostponedbookwormpackage

Примечания

  • https://curl.se/docs/CVE-2026-19931.html

  • Introduced with: https://github.com/curl/curl/commit/6c6035532383e300c712e4c1cd9fdd749ed5cf59 (curl-7_64_1)

  • Fixed by: https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d05d02fa9eeba533f2f (rc-8_22_0-2)

EPSS

Процентиль: 66%
0.01162
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

CVSS3: 6.5
redhat
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

CVSS3: 9.8
nvd
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

msrc
13 дней назад

Negotiate ambient user conn reuse

CVSS3: 9.8
github
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

EPSS

Процентиль: 66%
0.01162
Низкий