Allocation of Resources Without Limits or Throttling in cURL - CVE-2026-11586
Published: June 24, 2026
cURL
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the WebSocket auto-PONG handling when processing rapid sequential WebSocket PING frames from a server. A remote attacker can send rapid sequential PING frames to cause a denial of service.
This issue affects both libcurl and the curl command line tool.