Impact
A flaw in libcurl can cause an HTTP connection that was previously established for Negotiate authentication to be improperly reused when a new request is made with empty credentials. This means a second user can have their traffic routed over the first user's authenticated connection, allowing the second user to perform actions under the first user's identity. The impact is the potential for unauthorized access, data exposure and integrity violations for the victim user.
Affected Systems
The vulnerability affects libcurl, the network transfer library used by many applications. No specific affected versions are provided in the advisory, so all current and future releases that have not incorporated the fix could be at risk.
Risk and Exploitability
The CVSS score is not disclosed, and an EPSS score is unavailable, but the exploitability appears to require the attacker to control two distinct users who interact with the same server. The vulnerability is not listed in the CISA KEV catalog. Because the flaw involves reuse of authenticated connections, the likely attack path involves a local or remote attacker managing to force a victim to send a request with empty credentials and then use the victim's established session.
OpenCVE Enrichment