Intel

AIKIDO-2026-554272

libcurl is vulnerable to Authentication Bypass

Authentication BypassCVE-2026-19931 Published 6 days ago

55

Medium Risk

This Affects:

C++libcurl
7.64.1 - 8.21.0
Fixed in 8.22.0
Are you affected? Scan for Free

TL;DR

Negotiate authentication with empty credentials means the ambient user, whose identity lives outside libcurl. Reusing the connection for a later request still sends that request on the connection authenticated as the earlier ambient user, even when the ambient user has changed, so one user's request runs with another user's authenticated session. The fix stops that reuse for blank Negotiate credentials.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you reuse connections for Negotiate authentication with empty credentials.

Background info

libcurl is vulnerable to Authentication Bypass in versions 7.64.1 - 8.21.0.

How to fix this

Upgrade the libcurl and/or the curl.curl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform