Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19931

Опубликовано: 06 сент. 2026
Источник: redhat
CVSS3: 6.5

Описание

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

A flaw was found in libcurl. This vulnerability allows an attacker to reuse an HTTP connection set up for a given hostname using Negotiate authentication. When an initial request is made with empty credentials, a subsequent user's request can be sent over a previously authenticated connection belonging to another user. This could lead to information disclosure or unauthorized access to sensitive data.

Отчет

This Moderate flaw in libcurl allows for information disclosure when applications reuse HTTP connections with Negotiate authentication. If an initial request is made with empty credentials, a subsequent request from another user could be sent over the previously authenticated connection, potentially exposing sensitive data. This risk is specific to applications configured to use Negotiate authentication.

Меры по смягчению последствий

To mitigate this prevent connection reuse (CURLOPT_FORBID_REUSE) for transfers using Negotiate authentication with empty credentials and strictly isolate libcurl connection pools across different security principals. For defense-in-depth, enforce network boundaries to limit outbound HTTP access, mitigating the impact of any potential cross-session data exposure while pending upstream patches.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Affected
Red Hat Enterprise Linux 10curlAffected
Red Hat Enterprise Linux 10igvmAffected
Red Hat Enterprise Linux 10rustNot affected
Red Hat Enterprise Linux 10s390utilsAffected
Red Hat Enterprise Linux 10snphostAffected
Red Hat Enterprise Linux 10trusteeAffected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-488
https://bugzilla.redhat.com/show_bug.cgi?id=2529199curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

CVSS3: 9.8
nvd
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

msrc
13 дней назад

Negotiate ambient user conn reuse

CVSS3: 9.8
debian
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for ...

CVSS3: 9.8
github
14 дней назад

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

6.5 Medium

CVSS3