CVE-2026-19931: Haxx Curl
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
Affected products
- Haxx Curl: from 7.64.1, before 8.22.0 (fixed in 8.22.0)
Published 2026-09-06. Last modified 2026-09-15.