Curl · Libcurl · CVE-2026-19931
**Name of the Vulnerable Software and Affected Versions**
libcurl (affected versions not specified)
**Description**
A flaw exists where the software incorrectly reuses an HTTP connection setup for a specific hostname when using Negotiate authentication, specifically when the initial request is made with empty credentials. This behavior can lead to a situation where a request from one user is transmitted over a connection previously authenticated by another user.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.