CVE-2026-19931 is a critical (CVSS 3.1 base 9.8) connection-reuse flaw in libcurl, the HTTP library embedded in a vast range of applications and, notably, bundled with Windows — which is why this CVE surfaces in Microsoft’s own security-update data even though libcurl, not any Microsoft-authored code, is the actually vulnerable component.
What the vulnerability does
Per curl’s own advisory, libcurl can wrongly reuse an HTTP connection that was set up for a given hostname using Negotiate authentication, when the initial request on that connection was made with empty credentials. The practical effect: a request from “user B” can get sent over a connection that was previously authenticated as “user A” — in a multi-user process that shares a libcurl connection pool (a proxy, a multi-tenant service, an application handling requests on behalf of different accounts), this can leak one user’s authenticated session context to a different user’s request.
The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects a network-reachable, low-complexity flaw needing no privileges or user interaction, with high impact across confidentiality, integrity, and availability — consistent with one user’s traffic being exposed to or substituted for another’s.
Why this is filed under “Microsoft” in some feeds
libcurl ships as a bundled component in Windows, so Microsoft’s own CVRF security-update data includes this CVE in its monthly release alongside genuinely Microsoft-authored bulletins — the same pattern documented in our Patch Tuesday coverage for Azure Linux (Mariner) and Chromium/Edge CVEs. The real affected project is curl/libcurl, not Microsoft-authored code; treating it as a Microsoft vulnerability would misattribute the flaw to the wrong maintainer.
What we don’t yet have
No public proof-of-concept or evidence of active exploitation is documented for this CVE as of this writing, and it is not listed in CISA’s KEV catalog. Confidence is medium: the description and CVSS scoring trace to NVD/curl’s own advisory, but affected/fixed version ranges aren’t yet present in our ingested data — check curl’s own advisory for the specific version boundary before assuming a given build is affected.
Why this matters
Any application embedding libcurl and sharing connections across distinct authenticated users — reverse proxies, multi-tenant backends, credential-broker services — should treat this as a priority patch once a fixed libcurl version is confirmed available, given the confidentiality/integrity impact of one user’s traffic crossing into another’s authenticated session.
Frequently Asked Questions
What is CVE-2026-19931? A CVSS 9.8 critical vulnerability in libcurl where a connection authenticated via Negotiate for one user can be wrongly reused for a different user’s request.
Is this a Microsoft vulnerability? No — it’s a libcurl (curl project) vulnerability. It appears in Microsoft’s security-update data because Windows bundles libcurl, not because Microsoft authored the flawed code.
Is CVE-2026-19931 being actively exploited? Not as of this writing — it is not listed in CISA’s Known Exploited Vulnerabilities catalog.
Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.