Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-19931

Опубликовано: 06 сент. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
Версия от 7.64.1 (включая) до 8.22.0 (исключая)

EPSS

Процентиль: 66%
0.01162
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-488
CWE-488

Связанные уязвимости

CVSS3: 9.8
ubuntu
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

CVSS3: 6.5
redhat
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

msrc
13 дней назад

Negotiate ambient user conn reuse

CVSS3: 9.8
debian
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for ...

CVSS3: 9.8
github
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

EPSS

Процентиль: 66%
0.01162
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-488
CWE-488