Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-19931

Опубликовано: 08 сент. 2026
Источник: msrc
CVSS3: 6.5
EPSS Низкий

Описание

Negotiate ambient user conn reuse

Обновления

ПродуктСтатьяОбновление
azl3 curl 8.11.1-11 on Azure Linux 3.0

Показывать по

EPSS

Процентиль: 66%
0.01162
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

CVSS3: 6.5
redhat
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

CVSS3: 9.8
nvd
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

CVSS3: 9.8
debian
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for ...

CVSS3: 9.8
github
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

EPSS

Процентиль: 66%
0.01162
Низкий

6.5 Medium

CVSS3