CVE-2026-13608 (GCVE-0-2026-13608)
Vulnerability from cvelistv5
Published
2026-09-06 17:47
Modified
2026-09-15 06:02
CWE
  • CWE-923 - Improper Restriction of Communication Channel to Intended Endpoints
Summary
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
Impacted products
Vendor Product Version
curl curl Version: 7.82.0   
Version: 8.15.0   
Version: 8.17.0   
Version: 8.21.0   
Create a notification for this product.
   curl curl Version: eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4
Create a notification for this product.
   curl curl Version: 8.21.0
Version: 8.20.0
Version: 8.19.0
Version: 8.18.0
Version: 8.17.0
Version: 8.16.0
Version: 8.15.0
Version: 8.14.1
Version: 8.14.0
Version: 8.13.0
Version: 8.12.1
Version: 8.12.0
Version: 8.11.1
Version: 8.11.0
Version: 8.10.1
Version: 8.10.0
Version: 8.9.1
Version: 8.9.0
Version: 8.8.0
Version: 8.7.1
Version: 8.7.0
Version: 8.6.0
Version: 8.5.0
Version: 8.4.0
Version: 8.3.0
Version: 8.2.1
Version: 8.2.0
Version: 8.1.2
Version: 8.1.1
Version: 8.1.0
Version: 8.0.1
Version: 8.0.0
Version: 7.88.1
Version: 7.88.0
Version: 7.87.0
Version: 7.86.0
Version: 7.85.0
Version: 7.84.0
Version: 7.83.1
Version: 7.83.0
Version: 7.82.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "HIGH",
              "attackVector": "NETWORK",
              "availabilityImpact": "NONE",
              "baseScore": 7.4,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "NONE",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-13608",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-08T15:39:09.395825Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-923",
                "description": "CWE-923 Improper Restriction of Communication Channel to Intended Endpoints",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-08T15:39:45.194Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://hackerone.com/reports/3822248"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "curl",
          "vendor": "curl",
          "versions": [
            {
              "lessThan": "8.14.2",
              "status": "affected",
              "version": "7.82.0",
              "versionType": "semver"
            },
            {
              "lessThan": "8.16.1",
              "status": "affected",
              "version": "8.15.0",
              "versionType": "semver"
            },
            {
              "lessThan": "8.20.1",
              "status": "affected",
              "version": "8.17.0",
              "versionType": "semver"
            },
            {
              "lessThan": "8.22.0",
              "status": "affected",
              "version": "8.21.0",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "curl",
          "repo": "https://github.com/curl/curl.git",
          "vendor": "curl",
          "versions": [
            {
              "lessThan": "ea71c3b6b60e563651ea8596a975aef0c8199519",
              "status": "affected",
              "version": "eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "curl",
          "vendor": "curl",
          "versions": [
            {
              "status": "affected",
              "version": "8.21.0"
            },
            {
              "status": "affected",
              "version": "8.20.0"
            },
            {
              "status": "affected",
              "version": "8.19.0"
            },
            {
              "status": "affected",
              "version": "8.18.0"
            },
            {
              "status": "affected",
              "version": "8.17.0"
            },
            {
              "status": "affected",
              "version": "8.16.0"
            },
            {
              "status": "affected",
              "version": "8.15.0"
            },
            {
              "status": "affected",
              "version": "8.14.1"
            },
            {
              "status": "affected",
              "version": "8.14.0"
            },
            {
              "status": "affected",
              "version": "8.13.0"
            },
            {
              "status": "affected",
              "version": "8.12.1"
            },
            {
              "status": "affected",
              "version": "8.12.0"
            },
            {
              "status": "affected",
              "version": "8.11.1"
            },
            {
              "status": "affected",
              "version": "8.11.0"
            },
            {
              "status": "affected",
              "version": "8.10.1"
            },
            {
              "status": "affected",
              "version": "8.10.0"
            },
            {
              "status": "affected",
              "version": "8.9.1"
            },
            {
              "status": "affected",
              "version": "8.9.0"
            },
            {
              "status": "affected",
              "version": "8.8.0"
            },
            {
              "status": "affected",
              "version": "8.7.1"
            },
            {
              "status": "affected",
              "version": "8.7.0"
            },
            {
              "status": "affected",
              "version": "8.6.0"
            },
            {
              "status": "affected",
              "version": "8.5.0"
            },
            {
              "status": "affected",
              "version": "8.4.0"
            },
            {
              "status": "affected",
              "version": "8.3.0"
            },
            {
              "status": "affected",
              "version": "8.2.1"
            },
            {
              "status": "affected",
              "version": "8.2.0"
            },
            {
              "status": "affected",
              "version": "8.1.2"
            },
            {
              "status": "affected",
              "version": "8.1.1"
            },
            {
              "status": "affected",
              "version": "8.1.0"
            },
            {
              "status": "affected",
              "version": "8.0.1"
            },
            {
              "status": "affected",
              "version": "8.0.0"
            },
            {
              "status": "affected",
              "version": "7.88.1"
            },
            {
              "status": "affected",
              "version": "7.88.0"
            },
            {
              "status": "affected",
              "version": "7.87.0"
            },
            {
              "status": "affected",
              "version": "7.86.0"
            },
            {
              "status": "affected",
              "version": "7.85.0"
            },
            {
              "status": "affected",
              "version": "7.84.0"
            },
            {
              "status": "affected",
              "version": "7.83.1"
            },
            {
              "status": "affected",
              "version": "7.83.0"
            },
            {
              "status": "affected",
              "version": "7.82.0"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Eunsoo Kim (Autonomous Code Security team at Microsoft)"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Eunsoo Kim"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-923",
              "description": "Improper Restriction of Communication Channel to Intended Endpoints",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-15T06:02:45.788Z",
        "orgId": "2499f714-1537-4658-8207-48ae4bb9eae9",
        "shortName": "curl"
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-13608.json"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-13608.html"
        },
        {
          "url": "https://hackerone.com/reports/3822248"
        }
      ],
      "title": "OpenLDAP SASL authentication bypass",
      "x_generator": {
        "engine": "cvelib 1.8.0"
      },
      "x_osv": {
        "affected": [
          {
            "ranges": [
              {
                "events": [
                  {
                    "introduced": "7.82.0"
                  },
                  {
                    "fixed": "8.14.2"
                  },
                  {
                    "introduced": "8.15.0"
                  },
                  {
                    "fixed": "8.16.1"
                  },
                  {
                    "introduced": "8.17.0"
                  },
                  {
                    "fixed": "8.20.1"
                  },
                  {
                    "introduced": "8.21.0"
                  },
                  {
                    "fixed": "8.22.0"
                  }
                ],
                "type": "SEMVER"
              },
              {
                "events": [
                  {
                    "introduced": "eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4"
                  },
                  {
                    "fixed": "ea71c3b6b60e563651ea8596a975aef0c8199519"
                  }
                ],
                "repo": "https://github.com/curl/curl.git",
                "type": "GIT"
              }
            ],
            "versions": [
              "8.21.0",
              "8.20.0",
              "8.19.0",
              "8.18.0",
              "8.17.0",
              "8.16.0",
              "8.15.0",
              "8.14.1",
              "8.14.0",
              "8.13.0",
              "8.12.1",
              "8.12.0",
              "8.11.1",
              "8.11.0",
              "8.10.1",
              "8.10.0",
              "8.9.1",
              "8.9.0",
              "8.8.0",
              "8.7.1",
              "8.7.0",
              "8.6.0",
              "8.5.0",
              "8.4.0",
              "8.3.0",
              "8.2.1",
              "8.2.0",
              "8.1.2",
              "8.1.1",
              "8.1.0",
              "8.0.1",
              "8.0.0",
              "7.88.1",
              "7.88.0",
              "7.87.0",
              "7.86.0",
              "7.85.0",
              "7.84.0",
              "7.83.1",
              "7.83.0",
              "7.82.0"
            ]
          }
        ],
        "aliases": [
          "CVE-2026-13608"
        ],
        "credits": [
          {
            "name": "Eunsoo Kim (Autonomous Code Security team at Microsoft)",
            "type": "finder"
          },
          {
            "name": "Eunsoo Kim",
            "type": "remediation developer"
          }
        ],
        "database_specific": {
          "CWE": {
            "desc": "Improper Restriction of Communication Channel to Intended Endpoints",
            "id": "CWE-923"
          },
          "URL": "https://curl.se/docs/CVE-2026-13608.json",
          "affects": "both",
          "issue": "https://hackerone.com/reports/3822248",
          "last_affected": "8.21.0",
          "package": "curl",
          "severity": "Low",
          "www": "https://curl.se/docs/CVE-2026-13608.html"
        },
        "details": "A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation.",
        "id": "CURL-CVE-2026-13608",
        "modified": "2026-09-07T10:34:51.00Z",
        "published": "2026-09-02T08:00:00.00Z",
        "schema_version": "1.5.0",
        "summary": "OpenLDAP SASL authentication bypass"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "2499f714-1537-4658-8207-48ae4bb9eae9",
    "assignerShortName": "curl",
    "cveId": "CVE-2026-13608",
    "datePublished": "2026-09-06T17:47:01.951Z",
    "dateReserved": "2026-06-29T08:57:44.945Z",
    "dateUpdated": "2026-09-15T06:02:45.788Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 7.4, \"attackVector\": \"NETWORK\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"HIGH\", \"availabilityImpact\": \"NONE\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"HIGH\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-13608\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"poc\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-09-08T15:39:09.395825Z\"}}}], \"references\": [{\"url\": \"https://hackerone.com/reports/3822248\", \"tags\": [\"exploit\"]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-923\", \"description\": \"CWE-923 Improper Restriction of Communication Channel to Intended Endpoints\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-09-08T15:39:40.949Z\"}}], \"cna\": {\"title\": \"OpenLDAP SASL authentication bypass\", \"x_osv\": {\"id\": \"CURL-CVE-2026-13608\", \"aliases\": [\"CVE-2026-13608\"], \"credits\": [{\"name\": \"Eunsoo Kim (Autonomous Code Security team at Microsoft)\", \"type\": \"finder\"}, {\"name\": \"Eunsoo Kim\", \"type\": \"remediation developer\"}], \"details\": \"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\\nincomplete handshake sequence to be misinterpreted as a successful\\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\\nattack can inject a premature or shortcut response that bypasses complete peer\\nvalidation.\", \"summary\": \"OpenLDAP SASL authentication bypass\", \"affected\": [{\"ranges\": [{\"type\": \"SEMVER\", \"events\": [{\"introduced\": \"7.82.0\"}, {\"fixed\": \"8.14.2\"}, {\"introduced\": \"8.15.0\"}, {\"fixed\": \"8.16.1\"}, {\"introduced\": \"8.17.0\"}, {\"fixed\": \"8.20.1\"}, {\"introduced\": \"8.21.0\"}, {\"fixed\": \"8.22.0\"}]}, {\"repo\": \"https://github.com/curl/curl.git\", \"type\": \"GIT\", \"events\": [{\"introduced\": \"eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4\"}, {\"fixed\": \"ea71c3b6b60e563651ea8596a975aef0c8199519\"}]}], \"versions\": [\"8.21.0\", \"8.20.0\", \"8.19.0\", \"8.18.0\", \"8.17.0\", \"8.16.0\", \"8.15.0\", \"8.14.1\", \"8.14.0\", \"8.13.0\", \"8.12.1\", \"8.12.0\", \"8.11.1\", \"8.11.0\", \"8.10.1\", \"8.10.0\", \"8.9.1\", \"8.9.0\", \"8.8.0\", \"8.7.1\", \"8.7.0\", \"8.6.0\", \"8.5.0\", \"8.4.0\", \"8.3.0\", \"8.2.1\", \"8.2.0\", \"8.1.2\", \"8.1.1\", \"8.1.0\", \"8.0.1\", \"8.0.0\", \"7.88.1\", \"7.88.0\", \"7.87.0\", \"7.86.0\", \"7.85.0\", \"7.84.0\", \"7.83.1\", \"7.83.0\", \"7.82.0\"]}], \"modified\": \"2026-09-07T10:34:51.00Z\", \"published\": \"2026-09-02T08:00:00.00Z\", \"schema_version\": \"1.5.0\", \"database_specific\": {\"CWE\": {\"id\": \"CWE-923\", \"desc\": \"Improper Restriction of Communication Channel to Intended Endpoints\"}, \"URL\": \"https://curl.se/docs/CVE-2026-13608.json\", \"www\": \"https://curl.se/docs/CVE-2026-13608.html\", \"issue\": \"https://hackerone.com/reports/3822248\", \"affects\": \"both\", \"package\": \"curl\", \"severity\": \"Low\", \"last_affected\": \"8.21.0\"}}, \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"value\": \"Eunsoo Kim (Autonomous Code Security team at Microsoft)\"}, {\"lang\": \"en\", \"type\": \"remediation developer\", \"value\": \"Eunsoo Kim\"}], \"affected\": [{\"vendor\": \"curl\", \"product\": \"curl\", \"versions\": [{\"status\": \"affected\", \"version\": \"7.82.0\", \"lessThan\": \"8.14.2\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"8.15.0\", \"lessThan\": \"8.16.1\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"8.17.0\", \"lessThan\": \"8.20.1\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"8.21.0\", \"lessThan\": \"8.22.0\", \"versionType\": \"semver\"}], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://github.com/curl/curl.git\", \"vendor\": \"curl\", \"product\": \"curl\", \"versions\": [{\"status\": \"affected\", \"version\": \"eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4\", \"lessThan\": \"ea71c3b6b60e563651ea8596a975aef0c8199519\", \"versionType\": \"git\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"curl\", \"product\": \"curl\", \"versions\": [{\"status\": \"affected\", \"version\": \"8.21.0\"}, {\"status\": \"affected\", \"version\": \"8.20.0\"}, {\"status\": \"affected\", \"version\": \"8.19.0\"}, {\"status\": \"affected\", \"version\": \"8.18.0\"}, {\"status\": \"affected\", \"version\": \"8.17.0\"}, {\"status\": \"affected\", \"version\": \"8.16.0\"}, {\"status\": \"affected\", \"version\": \"8.15.0\"}, {\"status\": \"affected\", \"version\": \"8.14.1\"}, {\"status\": \"affected\", \"version\": \"8.14.0\"}, {\"status\": \"affected\", \"version\": \"8.13.0\"}, {\"status\": \"affected\", \"version\": \"8.12.1\"}, {\"status\": \"affected\", \"version\": \"8.12.0\"}, {\"status\": \"affected\", \"version\": \"8.11.1\"}, {\"status\": \"affected\", \"version\": \"8.11.0\"}, {\"status\": \"affected\", \"version\": \"8.10.1\"}, {\"status\": \"affected\", \"version\": \"8.10.0\"}, {\"status\": \"affected\", \"version\": \"8.9.1\"}, {\"status\": \"affected\", \"version\": \"8.9.0\"}, {\"status\": \"affected\", \"version\": \"8.8.0\"}, {\"status\": \"affected\", \"version\": \"8.7.1\"}, {\"status\": \"affected\", \"version\": \"8.7.0\"}, {\"status\": \"affected\", \"version\": \"8.6.0\"}, {\"status\": \"affected\", \"version\": \"8.5.0\"}, {\"status\": \"affected\", \"version\": \"8.4.0\"}, {\"status\": \"affected\", \"version\": \"8.3.0\"}, {\"status\": \"affected\", \"version\": \"8.2.1\"}, {\"status\": \"affected\", \"version\": \"8.2.0\"}, {\"status\": \"affected\", \"version\": \"8.1.2\"}, {\"status\": \"affected\", \"version\": \"8.1.1\"}, {\"status\": \"affected\", \"version\": \"8.1.0\"}, {\"status\": \"affected\", \"version\": \"8.0.1\"}, {\"status\": \"affected\", \"version\": \"8.0.0\"}, {\"status\": \"affected\", \"version\": \"7.88.1\"}, {\"status\": \"affected\", \"version\": \"7.88.0\"}, {\"status\": \"affected\", \"version\": \"7.87.0\"}, {\"status\": \"affected\", \"version\": \"7.86.0\"}, {\"status\": \"affected\", \"version\": \"7.85.0\"}, {\"status\": \"affected\", \"version\": \"7.84.0\"}, {\"status\": \"affected\", \"version\": \"7.83.1\"}, {\"status\": \"affected\", \"version\": \"7.83.0\"}, {\"status\": \"affected\", \"version\": \"7.82.0\"}], \"defaultStatus\": \"unaffected\"}], \"references\": [{\"url\": \"https://curl.se/docs/CVE-2026-13608.json\"}, {\"url\": \"https://curl.se/docs/CVE-2026-13608.html\"}, {\"url\": \"https://hackerone.com/reports/3822248\"}], \"x_generator\": {\"engine\": \"cvelib 1.8.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\\nincomplete handshake sequence to be misinterpreted as a successful\\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\\nattack can inject a premature or shortcut response that bypasses complete peer\\nvalidation.\"}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-923\", \"description\": \"Improper Restriction of Communication Channel to Intended Endpoints\"}]}], \"providerMetadata\": {\"orgId\": \"2499f714-1537-4658-8207-48ae4bb9eae9\", \"shortName\": \"curl\", \"dateUpdated\": \"2026-09-15T06:02:45.788Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2026-13608\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-09-15T06:02:45.788Z\", \"dateReserved\": \"2026-06-29T08:57:44.945Z\", \"assignerOrgId\": \"2499f714-1537-4658-8207-48ae4bb9eae9\", \"datePublished\": \"2026-09-06T17:47:01.951Z\", \"assignerShortName\": \"curl\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…