PT-2026-35892 · Curl+2 · Libcurl+2

Stefan Eissing

·

Published

2026-04-29

·

Updated

2026-06-05

·

CVE-2026-5545

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions libcurl (affected versions not specified)
Description A logical error in the connection pooling mechanism allows libcurl to reuse an incorrect connection during authenticated HTTP(S) requests to the same host. If an application first performs a request using Negotiate authentication with one set of credentials and subsequently attempts another request to the same server with different credentials while the initial connection is still active, the second request may wrongly reuse the existing connection. This results in the second request being sent over a connection still authenticated with the first user's credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5545
ECHO-EC69-C7B1-4F74
OESA-2026-2477
OPENSUSE-SU-2026:10674-1
RHSA-2026:12916
USN-8227-1

Affected Products

Linuxmint
Ubuntu
Libcurl