CVE-2026-1965

medium Red Hat
CVSS v3 Base Score
6.8
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Published: March 11, 2026
Last Modified: March 11, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in curl. When an application uses libcurl to make multiple Negotiate-authenticated HTTP or HTTPS requests to the same server with different credentials, libcurl may incorrectly reuse an existing connection. This logical error can cause a subsequent request to be sent using the authentication of a previous user, leading to an authentication bypass.

CWE

CWE-303

Affected Products

Confidential Compute AttestationLogging Subsystem for Red Hat OpenShiftRed Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9Red Hat Enterprise Linux AI (RHEL AI) 3Red Hat JBoss Core ServicesRed Hat OpenShift Container Platform 4

References