๐Ÿ” CVE Alert

CVE-2026-13608

HIGH 7.4

OpenLDAP SASL authentication bypass

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

CWE CWE-923
Vendor curl
Product curl
Published Sep 6, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for curl curl

Be the first to know when new high vulnerabilities affecting curl curl are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

curl / curl
7.82.0 < 8.14.2 8.15.0 < 8.16.1 8.17.0 < 8.20.1 8.21.0 < 8.22.0
curl / curl
eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4 < ea71c3b6b60e563651ea8596a975aef0c8199519
curl / curl
8.21.0 8.20.0 8.19.0 8.18.0 8.17.0 8.16.0 8.15.0 8.14.1 8.14.0 8.13.0 8.12.1 8.12.0 8.11.1 8.11.0 8.10.1 8.10.0 8.9.1 8.9.0 8.8.0 8.7.1 8.7.0 8.6.0 8.5.0 8.4.0 8.3.0 8.2.1 8.2.0 8.1.2 8.1.1 8.1.0 8.0.1 8.0.0 7.88.1 7.88.0 7.87.0 7.86.0 7.85.0 7.84.0 7.83.1 7.83.0 7.82.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
curl.se: https://curl.se/docs/CVE-2026-13608.json curl.se: https://curl.se/docs/CVE-2026-13608.html hackerone.com: https://hackerone.com/reports/3822248

Credits

Eunsoo Kim (Autonomous Code Security team at Microsoft) Eunsoo Kim