VDB

CVE-2026-13608

CVE-2026-13608 PUBLISHED CVSS 7.4 HIGH

Reported by curl · Published September 6, 2026

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

Risk Scores

CVSS 3.1
7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
curlcurl7.82.0, 8.15.0, 8.17.0
curlcurleeca818b1e8d1e61c2d4d833aed56ce4c510a9d4
curlcurl8.21.0, 8.20.0, 8.19.0
wolficurl0, 0
chainguardcurl0
curlcurl
alpinecurl0, 0, 0
curlcurl8.5.0, 8.4.0, 8.3.0

Timeline

  • CVE Published
  • Sep 3, 2026 PoC Published
  • Sep 7, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›