Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2025-30

An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which c...

JLSEC Published
Modified
Affected Packages
CURL_jll < 8.5.0+0
LibCURL_jll < 8.0.1+0
Aliases / Upstream
CVE-2023-27536

An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPTGSSAPIDELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPTGSSAPIDELEGATION option has been changed.

References