When reusing a connection, curl was doing case insensitive comparisons of username and password with the existing connections.
This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.
{
"affects": "both",
"CWE": {
"desc": "Improper Handling of Case Sensitivity",
"id": "CWE-178"
},
"last_affected": "7.50.3",
"severity": "Medium",
"www": "https://curl.se/docs/CVE-2016-8616.html",
"package": "curl",
"URL": "https://curl.se/docs/CVE-2016-8616.json"
}