Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rhw6-3rrg-mwjq

Опубликовано: 06 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

EPSS

Процентиль: 66%
0.01162
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-488

Связанные уязвимости

CVSS3: 9.8
ubuntu
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

CVSS3: 6.5
redhat
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

CVSS3: 9.8
nvd
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

msrc
13 дней назад

Negotiate ambient user conn reuse

CVSS3: 9.8
debian
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for ...

EPSS

Процентиль: 66%
0.01162
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-488