CVE-2026-19931

NameCVE-2026-19931
DescriptionA flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
curl (PTS)bookworm7.88.1-10+deb12u15vulnerable
bookworm (security)7.88.1-10+deb12u5vulnerable
trixie8.14.1-2+deb13u5vulnerable
forky8.21.0-2vulnerable
sid8.22.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
curlsource(unstable)8.22.0~rc2-1

Notes

[trixie] - curl <no-dsa> (Minor issue)
[bookworm] - curl <postponed> (Minor issue)
https://curl.se/docs/CVE-2026-19931.html
Introduced with: https://github.com/curl/curl/commit/6c6035532383e300c712e4c1cd9fdd749ed5cf59 (curl-7_64_1)
Fixed by: https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d05d02fa9eeba533f2f (rc-8_22_0-2)

Search for package or bug name: Reporting problems