Skip to main content
QUIETLYTIC
Vulnerability

curl Authentication Flaw (CVE-2026-19931)

CVE-2026-19931 is a CVSS 9.8 critical flaw in libcurl that can send one user's HTTP request over another user's already-Negotiate-authenticated connection.

CVE-2026-19931
Threat Level
CRITICAL
CVSS
9.8
Status
Monitored
Confidence
Medium
Affected Products
curl, libcurl

CVE-2026-19931 is a critical (CVSS 3.1 base 9.8) connection-reuse flaw in libcurl, the HTTP library embedded in a vast range of applications and, notably, bundled with Windows — which is why this CVE surfaces in Microsoft’s own security-update data even though libcurl, not any Microsoft-authored code, is the actually vulnerable component.

What the vulnerability does

Per curl’s own advisory, libcurl can wrongly reuse an HTTP connection that was set up for a given hostname using Negotiate authentication, when the initial request on that connection was made with empty credentials. The practical effect: a request from “user B” can get sent over a connection that was previously authenticated as “user A” — in a multi-user process that shares a libcurl connection pool (a proxy, a multi-tenant service, an application handling requests on behalf of different accounts), this can leak one user’s authenticated session context to a different user’s request.

The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects a network-reachable, low-complexity flaw needing no privileges or user interaction, with high impact across confidentiality, integrity, and availability — consistent with one user’s traffic being exposed to or substituted for another’s.

Why this is filed under “Microsoft” in some feeds

libcurl ships as a bundled component in Windows, so Microsoft’s own CVRF security-update data includes this CVE in its monthly release alongside genuinely Microsoft-authored bulletins — the same pattern documented in our Patch Tuesday coverage for Azure Linux (Mariner) and Chromium/Edge CVEs. The real affected project is curl/libcurl, not Microsoft-authored code; treating it as a Microsoft vulnerability would misattribute the flaw to the wrong maintainer.

What we don’t yet have

No public proof-of-concept or evidence of active exploitation is documented for this CVE as of this writing, and it is not listed in CISA’s KEV catalog. Confidence is medium: the description and CVSS scoring trace to NVD/curl’s own advisory, but affected/fixed version ranges aren’t yet present in our ingested data — check curl’s own advisory for the specific version boundary before assuming a given build is affected.

Why this matters

Any application embedding libcurl and sharing connections across distinct authenticated users — reverse proxies, multi-tenant backends, credential-broker services — should treat this as a priority patch once a fixed libcurl version is confirmed available, given the confidentiality/integrity impact of one user’s traffic crossing into another’s authenticated session.

Frequently Asked Questions

What is CVE-2026-19931? A CVSS 9.8 critical vulnerability in libcurl where a connection authenticated via Negotiate for one user can be wrongly reused for a different user’s request.

Is this a Microsoft vulnerability? No — it’s a libcurl (curl project) vulnerability. It appears in Microsoft’s security-update data because Windows bundles libcurl, not because Microsoft authored the flawed code.

Is CVE-2026-19931 being actively exploited? Not as of this writing — it is not listed in CISA’s Known Exploited Vulnerabilities catalog.


Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 curl.se

Related intelligence


Analyst tools