Security
Loading…

CVE-2026-19931

UNKNOWN
Description

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

Timeline
Published:September 6th, 2026 6:17 PM
Last modified:September 6th, 2026 6:17 PM
CVSS Scoring

No CVSS v3 score available

Source: NIST NVD · Data may lag official sources by up to one minute