curl vulnerability

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

Published 6 Sep 2026Updated 6 Sep 20263 sources
CVSS 0.0

Source timeline

CVE record published by NVDView source ↗