Executive brief
A vulnerability in the curl data transfer library could cause an application to send data using the wrong user's credentials. When an application makes multiple authenticated requests to the same server, curl may incorrectly reuse an existing connection established by a different user. This could lead to unauthorized data access or actions being performed under the wrong account identity.
Technical details
A logical error in libcurl's connection pooling mechanism allows for improper connection reuse when Negotiate authentication is involved. If an application performs a Negotiate-authenticated request as one user and subsequently attempts a request to the same host as a different user, libcurl may fail to validate the credential change and reuse the existing authenticated socket. This results in the second request being transmitted over a connection still authorized as the first user. The vulnerability affects versions 7.10.6 through 8.19.0 and is fixed in version 8.20.0. Mitigation is possible by disabling connection reuse via CURLOPT_FRESH_CONNECT.
Affected products
- haxx curl 7.10.6 to 8.19.0
- haxx libcurl 7.10.6 to 8.19.0
Timeline
- 2026-04-01: disclosed: Reported to curl project via HackerOne
- 2026-04-29: patched: Fixed in curl 8.20.0
- 2026-04-29: advisory: Project curl advisory published
- 2026-05-13: other: NVD publication date