---
id: CVE-2026-19931
title: |-
  A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
  hostname using Negotiate authentication, when the initial request is done
  using empty credentials
summary: |-
  A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
  hostname using Negotiate authentication, when the initial request is done
  using empty credentials. This can make user B's request get sent over user A's
  previo…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-488
  - CWE-613
vendor: haxx
product: curl
affected:
  - 'curl >= 7.64.1, < 8.22.0'
patched:
  - curl 8.22.0
published: '2026-09-06'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T07:16:27.290'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19931'
references:
  - url: 'https://curl.se/docs/CVE-2026-19931.html'
    label: 2499f714-1537-4658-8207-48ae4bb9eae9
  - url: 'https://curl.se/docs/CVE-2026-19931.json'
    label: 2499f714-1537-4658-8207-48ae4bb9eae9
  - url: 'https://hackerone.com/reports/3923520'
    label: 2499f714-1537-4658-8207-48ae4bb9eae9
  - url: 'https://hackerone.com/reports/3923520'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19931.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-19931'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2529199'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-19931'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19931'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63514'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63161'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
  - score-dispute
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-08T15:42:15.881334Z'
epss: 0.00747
epssPercentile: 0.52842
ingestedAt: '2026-09-07T09:08:15.583Z'
scores:
  nvd: 9.8
  vendor: 6.5
---

## Overview

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.

## Affected

- `curl >= 7.64.1, < 8.22.0`

## Remediation

Upgrade past the affected range:

- `curl 8.22.0`

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces, … · no fix planned: Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19931.json)
- **RHSA-2026:63514** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:63514)
- **RHSA-2026:63161** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63161)
