Impact
libcurl may reuse a Negotiate‑authenticated connection opened for one service when an application requests a different service on the same server. Due to a logical error in the pooling logic, the library fails to verify the authentication service type, allowing a request to wrongfully reuse a previous connection. This flaw permits an authorization bypass and is identified as CWE‑287.
Affected Systems
The vulnerability affects the libcurl library in any application that employs Negotiate authentication and connection pooling. Versions and patch status are not disclosed; any installation using these features remains at risk until updated.;
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low likelihood of exploitation. The likely attack vector involves a vulnerable application that can influence connection‑reuse decisions, such as prompting libcurl to reuse a pooled connection for a different service. Although the risk remains moderate, public exploitation is expected to be rare.
OpenCVE Enrichment
Ubuntu USN