SB2026100939 - Fedora 44 update for curl



SB2026100939 - Fedora 44 update for curl

Published: October 9, 2026

Security Bulletin ID SB2026100939
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Exposure of Data Element to Wrong Session (CVE-ID: CVE-2026-19931)

CWE-ID: CWE-488 - Exposure of Data Element to Wrong Session

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause requests to be sent over another user's previously authenticated connection.

The vulnerability exists due to exposure of data element to wrong session in HTTP connection reuse for Negotiate authentication when reusing a connection established with empty credentials. A remote user can issue a request using blank credentials to cause requests to be sent over another user's previously authenticated connection.

This issue affects libcurl and the curl command line tool when Negotiate authentication is used with ambient credentials provided by SSPI or GSSAPI.


Remediation

Install update from vendor's website.