Exposure of Data Element to Wrong Session in cURL - CVE-2026-19931

 

Exposure of Data Element to Wrong Session in cURL - CVE-2026-19931

Published: September 2, 2026


Vulnerability identifier: #VU146683
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-19931
CWE-ID: CWE-488
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause requests to be sent over another user's previously authenticated connection.

The vulnerability exists due to exposure of data element to wrong session in HTTP connection reuse for Negotiate authentication when reusing a connection established with empty credentials. A remote user can issue a request using blank credentials to cause requests to be sent over another user's previously authenticated connection.

This issue affects libcurl and the curl command line tool when Negotiate authentication is used with ambient credentials provided by SSPI or GSSAPI.


Affected software

cURL

How to mitigate CVE-2026-19931

Install security update from vendor's website.

cURL - update to 8.22.0

External References

Related Security Bulletins