THREAT OPS › Threat News › [NVD] CVE-2026-1965 (MEDIUM 6.5) — libcurl can in some circumstances reuse the wrong connection when asked to do
an Negotiate-authenticated HTTP or HTTPS request.
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connectio
[NVD] CVE-2026-1965 (MEDIUM 6.5) — libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connectio
CVE-2026-1965 CVSS: 6.5 MEDIUM Published: 2026-03-11T11:15:59.177
libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.
libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.
When reusing a connection a range of criterion must first be met. Due to a lo
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-1965cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-1965