Количество 6
Количество 6
CVE-2026-19931
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
CVE-2026-19931
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
CVE-2026-19931
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
CVE-2026-19931
Negotiate ambient user conn reuse
CVE-2026-19931
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for ...
GHSA-rhw6-3rrg-mwjq
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-19931 A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection. | CVSS3: 9.8 | 1% Низкий | 14 дней назад | |
CVE-2026-19931 A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection. | CVSS3: 6.5 | 1% Низкий | 14 дней назад | |
CVE-2026-19931 A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection. | CVSS3: 9.8 | 1% Низкий | 14 дней назад | |
CVE-2026-19931 Negotiate ambient user conn reuse | 1% Низкий | 13 дней назад | ||
CVE-2026-19931 A flaw in libcurl makes it wrongly reuse an HTTP connection setup for ... | CVSS3: 9.8 | 1% Низкий | 14 дней назад | |
GHSA-rhw6-3rrg-mwjq A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection. | CVSS3: 9.8 | 1% Низкий | 14 дней назад |
Уязвимостей на страницу