Authentication Bypass by Capture-replay in cURL - CVE-2026-11856

 

Authentication Bypass by Capture-replay in cURL - CVE-2026-11856

Published: June 24, 2026


Vulnerability identifier: #VU135075
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-11856
CWE-ID: CWE-294
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication by replaying Digest authentication state.

The vulnerability exists due to authentication bypass by capture-replay in libcurl Digest authentication handling when reusing the same handle for a second transfer to a different HTTP origin. A remote attacker can receive a request containing an Authorization header intended for another origin to bypass authentication by replaying Digest authentication state.

The issue affects libcurl but not the curl command line tool. The leaked header does not reveal the other origin, and the exposed state allows replay only for the exact path of the captured request.


Affected software

cURL
LANTIME Operating System Firmware (LTOS)
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
openEuler
Anolis OS
Fedora
curl (Ubuntu package)
curl-help
libcurl-devel
libcurl
curl-debugsource
curl-debuginfo
curl
curl-doc
libcurl-minimal
curl-minimal
curl (Red Hat package)

How to mitigate CVE-2026-11856

Install security update from vendor's website.

cURL - update to 8.21.0
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm22, 7.47.0-1ubuntu2.19+esm18, 7.58.0-2ubuntu3.24+esm11, 7.68.0-1ubuntu2.25+esm6, 7.81.0-1ubuntu1.26, 8.5.0-2ubuntu10.12, 8.18.0-1ubuntu2.4
curl-help - addressed in versions 7.71.1-52, 7.71.1-54, 7.79.1-53, 7.79.1-56, 8.4.0-35, 8.4.0-37
libcurl-devel - addressed in versions 7.71.1-52, 7.71.1-54, 7.79.1-53, 7.79.1-56, 8.4.0-35, 8.4.0-37
libcurl - addressed in versions 7.71.1-52, 7.71.1-54, 7.79.1-53, 7.79.1-56, 8.4.0-35, 8.4.0-37
curl-debugsource - addressed in versions 7.71.1-52, 7.71.1-54, 7.79.1-53, 7.79.1-56, 8.4.0-35, 8.4.0-37
curl-debuginfo - addressed in versions 7.71.1-52, 7.71.1-54, 7.79.1-53, 7.79.1-56, 8.4.0-35, 8.4.0-37
curl - addressed in versions 7.71.1-52, 7.71.1-54, 7.79.1-53, 7.79.1-56, 8.4.0-35, 8.4.0-37
curl-doc - update to 8.4.0-26
libcurl-minimal - update to 8.4.0-26
libcurl-devel - update to 8.4.0-26
libcurl - update to 8.4.0-26
curl-minimal - update to 8.4.0-26
curl - update to 8.4.0-26
curl (Red Hat package) - update to 8.12.1-1.el10_0.10
curl - addressed in versions 8.15.0-8.fc43, 8.18.0-8.fc44

External References

Related Security Bulletins