CVE-2026-19931

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
References
Link Resource
https://curl.se/docs/CVE-2026-19931.html Patch Vendor Advisory
https://curl.se/docs/CVE-2026-19931.json Vendor Advisory
https://hackerone.com/reports/3923520 Exploit Mitigation Third Party Advisory
https://hackerone.com/reports/3923520 Exploit Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-06 18:17

Updated : 2026-09-15 07:16


NVD link : CVE-2026-19931

Mitre link : CVE-2026-19931

CVE.ORG link : CVE-2026-19931


JSON object : View

Products Affected

haxx

  • curl
CWE
CWE-488

Exposure of Data Element to Wrong Session