HTTP Connection Reuse Flaw in libcurl Affecting Multiple Versions
CVE-2026-19931

Currently unrated

Key Information:

Vendor

Curl

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-19931?

A vulnerability within libcurl allows for the improper reuse of HTTP connections established via Negotiate authentication when initial requests are made with empty credentials. This situation can lead to sensitive information being inadvertently exposed, as user B's requests may be sent through the authenticated connection of user A. Organizations using affected versions of libcurl should assess their risk and take appropriate action to mitigate potential security breaches.

Affected Version(s)

curl 8.21.0

curl 8.20.0

curl 8.19.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Martin Dukek
Stefan Eissing
.