PT-2026-35892 · Curl+2 · Libcurl+2
Stefan Eissing
·
Published
2026-04-29
·
Updated
2026-06-05
·
CVE-2026-5545
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
libcurl (affected versions not specified)
Description
A logical error in the connection pooling mechanism allows libcurl to reuse an incorrect connection during authenticated HTTP(S) requests to the same host. If an application first performs a request using Negotiate authentication with one set of credentials and subsequently attempts another request to the same server with different credentials while the initial connection is still active, the second request may wrongly reuse the existing connection. This results in the second request being sent over a connection still authenticated with the first user's credentials.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Libcurl