Impact
libcurl has a flaw in its connection-reuse logic for Negotiate-authenticated HTTP or HTTPS requests. When an application authenticates a connection with one set of credentials (user1) and later issues another Negotiate request with a different set (user2) to the same server while the original connection is still open, the library incorrectly reuses the same socket. Because Negotiate can authenticate at the connection level, libcurl assumes the link is already authenticated and sends the second request using the original credentials. This improper authentication weakness, CWE-305, allows a client to access resources as a different user, permitting unauthorized data or service access.
Affected Systems
The vulnerability affects the curl:curl product, i.e., libcurl. No specific product‑version range is listed in the CVE record, so all releases prior to the fix are potentially impacted. The affected platform is identified by the CPE string cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*.
Risk and Exploitability
The CVSS base score is 6.5, which classifies the issue as Medium severity. The EPSS score is reported as less than 1 %, indicating a low probability that the vulnerability will be actively exploited at any given time. The vulnerability is not included in the CISA KEV catalog. Based on the description, the likely attack vector involves an application that performs two Negotiate-authenticated requests to the same server with different credentials; an attacker who controls the application or its configuration can drive the second request to reuse the prior connection, achieving unauthorized access. Exploitation requires the client to make both requests to the same server while the original connection remains open, and does not require any special permissions or lateral movement once the client is compromised.
OpenCVE Enrichment
Ubuntu USN