Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-19931: curl may send one user’s request using another’s login
CVE-2026-19931 · published 21 days ago
Summary
The curl tool can mistakenly reuse an HTTP connection that was authenticated with one user when a later request is made without credentials. This can cause a request from user B to be sent over a connection that was already authenticated for user A, potentially exposing data. Update curl to the latest version or configure it to avoid connection reuse for Negotiate authentication.
What to do
- Update bellsoft curl to version 8.22.0-r0.
- Update curl to version 8.22.0-r0.
- Update curl to version 8.14.1-2+deb13u5.aikido.19.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.19.
- Update curl to version 8.14.1-r30075.
- Update rootio-curl to version 8.14.1-r30075.
- Update curl to version 8.14.1-r30076.
- Update rootio-curl to version 8.14.1-r30076.
- Update curl to version 7.88.1-10+deb12u15.aikido.16.
- Update rootio-curl to version 7.88.1-10+deb12u15.aikido.16.
- Update curl to version 8.14.1-r200711.
- Update rootio-curl to version 8.14.1-r200711.
- Update curl to version 8.5.0-r00073.
- Update rootio-curl to version 8.5.0-r00073.
- Update curl to version 8.14.1-r30077.
- Update rootio-curl to version 8.14.1-r30077.
- Update curl to version 8.14.1-r20075.
- Update rootio-curl to version 8.14.1-r20075.
- Update debian curl to version 8.22.0~rc2-1.
- Update curl to version 8.14.1-2+deb13u5.aikido.20.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.20.
- Update haxx curl to version 8.22.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | curl | curl |
<= 8.21.0 < 8.14.2 < 7103a93b05bc69ea98ed9d05d02fa9eeba533f2f 8.21.0 |
| Ubuntu:Pro:14.04:LTS | canonical | curl | All versions |
| Alpaquita:23 | bellsoft | curl |
>= 8.1.0-r2, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| Alpaquita:25 | bellsoft | curl |
>= 8.14.0-r1, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| Alpaquita:stream | bellsoft | curl |
>= 8.1.2-r0, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| BellSoft Hardened Containers:stream | bellsoft | curl |
>= 8.1.2-r0, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| Debian:12 | debian | curl | All versions |
| BellSoft Hardened Containers:stream | – | curl |
>= 8.1.2-r0, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| – | haxx | curl |
>= 7.64.1, < 8.22.0 cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* |
| Alpine:v3.23 | – | curl |
< 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| Root:Debian:13 | – | curl |
< 8.14.1-2+deb13u5.aikido.19 < 8.14.1-2+deb13u5.aikido.20 Fix: upgrade to 8.14.1-2+deb13u5.aikido.19
|
| Root:Debian:13 | – | rootio-curl |
< 8.14.1-2+deb13u5.aikido.19 < 8.14.1-2+deb13u5.aikido.20 Fix: upgrade to 8.14.1-2+deb13u5.aikido.19
|
| Root:Alpine:3.22 | – | curl |
< 8.14.1-r30075 < 8.14.1-r30076 < 8.14.1-r30077 Fix: upgrade to 8.14.1-r30075
|
| Root:Alpine:3.22 | – | rootio-curl |
< 8.14.1-r30075 < 8.14.1-r30076 < 8.14.1-r30077 Fix: upgrade to 8.14.1-r30075
|
| Root:Debian:12 | – | curl |
< 7.88.1-10+deb12u15.aikido.16 Fix: upgrade to 7.88.1-10+deb12u15.aikido.16
|
| Root:Debian:12 | – | rootio-curl |
< 7.88.1-10+deb12u15.aikido.16 Fix: upgrade to 7.88.1-10+deb12u15.aikido.16
|
| Root:Alpine:3.20 | – | curl |
< 8.14.1-r200711 Fix: upgrade to 8.14.1-r200711
|
| Root:Alpine:3.20 | – | rootio-curl |
< 8.14.1-r200711 Fix: upgrade to 8.14.1-r200711
|
| Root:Alpine:3.15 | – | curl |
< 8.5.0-r00073 Fix: upgrade to 8.5.0-r00073
|
| Root:Alpine:3.15 | – | rootio-curl |
< 8.5.0-r00073 Fix: upgrade to 8.5.0-r00073
|
| Root:Alpine:3.21 | – | curl |
< 8.14.1-r20075 Fix: upgrade to 8.14.1-r20075
|
| Root:Alpine:3.21 | – | rootio-curl |
< 8.14.1-r20075 Fix: upgrade to 8.14.1-r20075
|
| Debian:14 | debian | curl |
< 8.22.0~rc2-1 Fix: upgrade to 8.22.0~rc2-1
|
Original advisory text
Negotiate ambient user conn reuse
A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
References
- https://docs.bell-sw.com/security/cves/CVE-2026-19931 Vendor Advisory
- https://curl.se/docs/CVE-2026-19931.html Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-19931 Vendor Advisory
- https://curl.se/docs/CVE-2026-19931.json URL
- https://github.com/curl/curl.git Product
- https://www.cve.org/CVERecord?id=CVE-2026-19931 Third Party Advisory
- https://security.alpinelinux.org/vuln/CVE-2026-19931 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19931... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-19931 Vendor Advisory
- https://hackerone.com/reports/3923520 URL
- https://ubuntu.com/security/CVE-2026-19931 Third Party Advisory
- https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d Third Party Advisory
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-488Exposure of Data Element to Wrong Session
Timeline
Published6 Sep 2026
Updated27 Sep 2026
First seen2 Sep 2026
Sources
CURL-CVE-2026-19931 · OSV
CVE-2026-19931 · NVD
UBUNTU-CVE-2026-19931 · OSV
BELL-CVE-2026-19931 · OSV
CVE-2026-19931 · MITRE
DEBIAN-CVE-2026-19931 · OSV
ALPINE-CVE-2026-19931 · OSV
CVE-2026-19931 · OSV
Track software like this
Free during beta