Impact
An application that uses libcurl to perform authenticated HTTP(S) requests may incorrectly reuse a connection created with Negotiate authentication. This flaw, documented as CWE-305, CWE-488, and CWE-613, allows a second request to the same host to be sent over the existing connection that has been authenticated for a different user, effectively mixing credentials. The result is an authentication bypass that can expose resources or data that should be restricted to the original authenticated user.
Affected Systems
Any software built against libcurl that performs Negotiate‑authenticated calls to the same host is potentially vulnerable. No specific vendor, product, or version data has been disclosed, so the risk applies broadly to libcurl‑based applications that reuse connections across authentication contexts.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of < 1 % shows a very low exploit probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote; an attacker must be able to trigger a second request via the vulnerable application or manipulate the target host to provoke the flawed reuse. Because the flaw originates from logical logic in libcurl’s connection pooling, exploitation requires control over the authenticated requests or the target API but does not rely on internal vulnerabilities in the application or the server.
OpenCVE Enrichment
Ubuntu USN