https://seclists.org/oss-sec/2026/q1/291: [ADVISORY] curl: CVE-2026-1965: bad use of HTTP Negotiate connection
Published Mar 11, 2026
·Updated
Affected Software
1 affected component
redhat/libcurl>=7.10.6<=8.18.0
Frequently Asked Questions
1
What is the severity of CVE-2026-1965?
CVE-2026-1965 is classified as a high-severity vulnerability due to its potential impact on security protocols.
2
How do I fix CVE-2026-1965?
To fix CVE-2026-1965, update libcurl to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2026-1965?
CVE-2026-1965 is a connection reuse issue that affects the HTTP Negotiate authentication mechanism.
4
Which software is affected by CVE-2026-1965?
CVE-2026-1965 affects the libcurl library used in various applications for handling HTTP connections.
5
When was CVE-2026-1965 published?
CVE-2026-1965 was published on March 11, 2026.