CVE-2026-19931
published 2026-09-06CVE-2026-19931: A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using…
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.75%
53.3th percentile
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
Affected
74 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
curl libcurl up to 8.21.0 Connection Reuse wrong session (EUVD-2026-72166)
vuldb·2026-09-06
CVE-2026-19931 [CRITICAL] curl libcurl up to 8.21.0 Connection Reuse wrong session (EUVD-2026-72166)
A vulnerability described as critical has been identified in curl libcurl. This impacts an unknown function of the component Connection Reuse. The manipulation results in exposure of data element to wrong session.
This vulnerability is cataloged as CVE-2026-19931. The attack may be launched remotely. There is no exploit available.
GHSA
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials.
ghsa_unreviewed·2026-09-06
CVE-2026-19931 A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
Red Hat
curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication
vendor_redhat·2026-09-06·CVSS 9.8
CVE-2026-19931 [CRITICAL] CWE-613 curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication
curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
A flaw was found in libcurl. This vulnerability allows an attacker to reuse an HTTP connection set up for a given hostname using Negotiate authentication. When an initial request is made with empty credentials, a subsequent user's request can be sent over a previously authenticated connection belonging to another user. This could lead to information disclosure or unauthorized access to sensitive data.
Package: curl (Red Hat Ha
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-19931 rpi-imager: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
bugzilla·2026-09-17·CVSS 9.8
CVE-2026-19931 [CRITICAL] CVE-2026-19931 rpi-imager: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
CVE-2026-19931 rpi-imager: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
Bugzilla
CVE-2026-19931 trustee-guest-components: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
bugzilla·2026-09-17·CVSS 9.8
CVE-2026-19931 [CRITICAL] CVE-2026-19931 trustee-guest-components: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
CVE-2026-19931 trustee-guest-components: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
Bugzilla
CVE-2026-19931 curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
bugzilla·2026-09-17·CVSS 9.8
CVE-2026-19931 [CRITICAL] CVE-2026-19931 curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
CVE-2026-19931 curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
Bugzilla
CVE-2026-19931 rust: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
bugzilla·2026-09-17·CVSS 9.8
CVE-2026-19931 [CRITICAL] CVE-2026-19931 rust: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
CVE-2026-19931 rust: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
Discussion:
The bundled `curl` sources (via the Rust `curl-sys` crate) are wholly removed during the `%prep` phase to be sure we don't use them. Instead, we use the system `curl
Bugzilla
CVE-2026-19931 rustup: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
bugzilla·2026-09-17·CVSS 9.8
CVE-2026-19931 [CRITICAL] CVE-2026-19931 rustup: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
CVE-2026-19931 rustup: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
Discussion:
This package dynamically links system-provided libcurl, and does not include code from curl itself.
So the issue needs to be fixed in curl, and nothing can be done
Bugzilla
CVE-2026-19931 nushell: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [epel-all]
bugzilla·2026-09-17·CVSS 9.8
CVE-2026-19931 [CRITICAL] CVE-2026-19931 nushell: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [epel-all]
CVE-2026-19931 nushell: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
Discussion:
This package dynamically links system-provided libcurl, and does not include code from curl itself.
So the issue needs to be fixed in curl, and nothing can be done
Bugzilla
CVE-2026-19931 mingw-curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
bugzilla·2026-09-17·CVSS 9.8
CVE-2026-19931 [CRITICAL] CVE-2026-19931 mingw-curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
CVE-2026-19931 mingw-curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
Bugzilla
CVE-2026-19931 stgit: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
bugzilla·2026-09-17·CVSS 9.8
CVE-2026-19931 [CRITICAL] CVE-2026-19931 stgit: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
CVE-2026-19931 stgit: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
Discussion:
This package dynamically links system-provided libcurl, and does not include code from curl itself.
So the issue needs to be fixed in curl, and nothing can be done
Bugzilla
CVE-2026-19931 nushell: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
bugzilla·2026-09-17·CVSS 9.8
CVE-2026-19931 [CRITICAL] CVE-2026-19931 nushell: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
CVE-2026-19931 nushell: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
Discussion:
This package dynamically links system-provided libcurl, and does not include code from curl itself.
So the issue needs to be fixed in curl, and nothing can be don
Bugzilla
CVE-2026-19931 curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication
bugzilla·2026-09-06·CVSS 9.8
CVE-2026-19931 [CRITICAL] CVE-2026-19931 curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication
CVE-2026-19931 curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. This can make user B's request get sent over user A's
previously authenticated connection.
Rapid7
Patch Tuesday - September 2026
blogs_rapid7·2026-09-08·CVSS 7.8
CVE-2026-85880 [HIGH] Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today.
## Windows ALPC: zero-day EoP
The eternal game of elevation of privilege whack-a-mole between Microsoft and attackers continues. This month, the batt
2026-09-06
Published