{"id":"CVE-2026-19931","title":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials","summary":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\nprevio…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-488","CWE-613"],"vendor":"haxx","product":"curl","affected":["curl >= 7.64.1, < 8.22.0"],"patched":["curl 8.22.0"],"published":"2026-09-06","updated":"2026-09-15","sourceUpdated":"2026-09-15T07:16:27.290","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","references":[{"url":"https://curl.se/docs/CVE-2026-19931.html","label":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"url":"https://curl.se/docs/CVE-2026-19931.json","label":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"url":"https://hackerone.com/reports/3923520","label":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"url":"https://hackerone.com/reports/3923520","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19931.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-19931"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2529199"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-19931"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931"},{"url":"https://access.redhat.com/errata/RHSA-2026:63514"},{"url":"https://access.redhat.com/errata/RHSA-2026:63161"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat","score-dispute"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-08T15:42:15.881334Z"},"epss":0.01162,"epssPercentile":0.65847,"ingestedAt":"2026-09-07T09:08:15.583Z","scores":{"nvd":9.8,"vendor":6.5},"slug":"CVE-2026-19931","body":"## Overview\n\nA flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection.\n\n## Affected\n\n- `curl >= 7.64.1, < 8.22.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `curl 8.22.0`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces, … · no fix planned: Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19931.json)\n- **RHSA-2026:63514** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:63514)\n- **RHSA-2026:63161** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63161)","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":4991,"id":"CVE-2026-19931","ts":1788887224880,"field":"exploit_available","old":"false","new":"true"},{"seq":4990,"id":"CVE-2026-19931","ts":1788887224880,"field":"cvss","old":null,"new":"9.8"},{"seq":4989,"id":"CVE-2026-19931","ts":1788887224880,"field":"severity","old":"none","new":"critical"},{"seq":3874,"id":"CVE-2026-19931","ts":1788886357109,"field":"exploit_available","old":"true","new":"false"},{"seq":3873,"id":"CVE-2026-19931","ts":1788886357109,"field":"cvss","old":"9.8","new":null},{"seq":3872,"id":"CVE-2026-19931","ts":1788886357109,"field":"severity","old":"critical","new":"none"},{"seq":3294,"id":"CVE-2026-19931","ts":1788885294187,"field":"exploit_available","old":"false","new":"true"},{"seq":3293,"id":"CVE-2026-19931","ts":1788885294187,"field":"cvss","old":null,"new":"9.8"},{"seq":3292,"id":"CVE-2026-19931","ts":1788885294187,"field":"severity","old":"none","new":"critical"}]}