Impact
libcurl may reuse the wrong connection when an application requests Negotiate‑authenticated requests, even if the connections are intended for different services. Because of a logical error in the connection‑reuse criteria, the library can allow a request to reuse an existing connection that was previously authenticated for a different service on the same server. This flaw could let to access services for which they have no authorization, potentially exposing sensitive data or altering service behavior.
Affected Systems
Applications that link against libcurl and enable Negotiate authentication while using connection pooling are affected. The vendor is curl. No specific product versions are disclosed, so any installation that uses these features is considered potentially vulnerable until the fix is applied.
Risk and Exploitability
Risk assessment shows a CVSS score of 6.5, indicating moderate severity. The EPSS score of fewer than 1 % and absence from the CISA KEV catalog suggest that exploitation is unlikely under current threat conditions. The attack vector is inferred to be remote or local misuse of libcurl by an attacker who can influence the application’s request patterns. However, because the CVE description does not specify additional prerequisites, the exact likelihood remains uncertain, and the overall risk to an environment depends on the prevalence of Negotiate‑authenticated, pooled connections.
OpenCVE Enrichment
Ubuntu USN