Description
libcurl might in some circumstances reuse the wrong connection when asked to
do an authenticated HTTP(S) request after a Negotiate-authenticated one, when
both use the same host.

libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.

When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a request that was issued by an application could
wrongfully reuse an existing connection to the same server that was
authenticated using different credentials.

An application that first uses Negotiate authentication to a server with
`user1:password1` and then does another operation to the same server asking
for any authentication method but for `user2:password2` (while the previous
connection is still alive) - the second request gets confused and wrongly
reuses the same connection and sends the new request over that connection
thinking it uses a mix of user1's and user2's credentials when it is in fact
still using the connection authenticated for user1...
Published: 2026-05-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass via libcurl connection reuse leading to unauthorized access or data leakage
Action: Apply Patch
AI Analysis

Impact

An application that uses libcurl to perform authenticated HTTP(S) requests may incorrectly reuse a connection created with Negotiate authentication. This flaw, documented as CWE-305, CWE-488, and CWE-613, allows a second request to the same host to be sent over the existing connection that has been authenticated for a different user, effectively mixing credentials. The result is an authentication bypass that can expose resources or data that should be restricted to the original authenticated user.

Affected Systems

Any software built against libcurl that performs Negotiate‑authenticated calls to the same host is potentially vulnerable. No specific vendor, product, or version data has been disclosed, so the risk applies broadly to libcurl‑based applications that reuse connections across authentication contexts.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of < 1 % shows a very low exploit probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote; an attacker must be able to trigger a second request via the vulnerable application or manipulate the target host to provoke the flawed reuse. Because the flaw originates from logical logic in libcurl’s connection pooling, exploitation requires control over the authenticated requests or the target API but does not rely on internal vulnerabilities in the application or the server.

Generated by OpenCVE AI on September 21, 2026 at 08:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libcurl to the latest release that incorporates the CVE‑2026‑5545 fix.
  • If an immediate upgrade is not feasible, configure the application to disable connection reuse for requests that involve Negotiate authentication, ensuring each request establishes a fresh TCP connection.
  • Implement runtime checks to validate the authentication state before sending each request, or review and enforce proper authentication context handling to prevent accidental credential mixing across connections.

Generated by OpenCVE AI on September 21, 2026 at 08:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8227-1 curl vulnerabilities
Ubuntu USN Ubuntu USN USN-8525-1 curl vulnerabilities
History

Tue, 15 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-305

Wed, 13 May 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Haxx
Haxx curl
Weaknesses CWE-613
CPEs cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
Vendors & Products Haxx
Haxx curl

Wed, 13 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}


Wed, 13 May 2026 09:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure. libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1...
Title curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse wrong reuse of HTTP Negotiate connection
References

Fri, 01 May 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Curl
Curl libcurl
Vendors & Products Curl
Curl libcurl

Fri, 01 May 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure.
Title curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse
Weaknesses CWE-488
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: curl

Published:

Updated: 2026-09-15T06:02:59.285Z

Reserved: 2026-04-04T12:10:07.125Z

Link: CVE-2026-5545

cve-icon Vulnrichment

Updated: 2026-05-13T17:46:02.178Z

cve-icon NVD

Status : Modified

Published: 2026-05-13T13:01:56.190

Modified: 2026-09-15T07:16:28.633

Link: CVE-2026-5545

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-04-29T00:00:00Z

Links: CVE-2026-5545 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T08:30:13Z

Weaknesses
  • CWE-305

    Authentication Bypass by Primary Weakness

  • CWE-488

    Exposure of Data Element to Wrong Session

  • CWE-613

    Insufficient Session Expiration