Authentication Bypass by Capture-replay in cURL - CVE-2026-11856
Published: June 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication by replaying Digest authentication state.
The vulnerability exists due to authentication bypass by capture-replay in libcurl Digest authentication handling when reusing the same handle for a second transfer to a different HTTP origin. A remote attacker can receive a request containing an Authorization header intended for another origin to bypass authentication by replaying Digest authentication state.
The issue affects libcurl but not the curl command line tool. The leaked header does not reveal the other origin, and the exposed state allows replay only for the exact path of the captured request.
Affected software
LANTIME Operating System Firmware (LTOS)
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
openEuler
Anolis OS
Fedora
curl (Ubuntu package)
curl-help
libcurl-devel
libcurl
curl-debugsource
curl-debuginfo
curl
curl-doc
libcurl-minimal
curl-minimal
curl (Red Hat package)
How to mitigate CVE-2026-11856
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm22, 7.47.0-1ubuntu2.19+esm18, 7.58.0-2ubuntu3.24+esm11, 7.68.0-1ubuntu2.25+esm6, 7.81.0-1ubuntu1.26, 8.5.0-2ubuntu10.12, 8.18.0-1ubuntu2.4
curl-help - addressed in versions 7.71.1-52, 7.71.1-54, 7.79.1-53, 7.79.1-56, 8.4.0-35, 8.4.0-37
libcurl-devel - addressed in versions 7.71.1-52, 7.71.1-54, 7.79.1-53, 7.79.1-56, 8.4.0-35, 8.4.0-37
libcurl - addressed in versions 7.71.1-52, 7.71.1-54, 7.79.1-53, 7.79.1-56, 8.4.0-35, 8.4.0-37
curl-debugsource - addressed in versions 7.71.1-52, 7.71.1-54, 7.79.1-53, 7.79.1-56, 8.4.0-35, 8.4.0-37
curl-debuginfo - addressed in versions 7.71.1-52, 7.71.1-54, 7.79.1-53, 7.79.1-56, 8.4.0-35, 8.4.0-37
curl - addressed in versions 7.71.1-52, 7.71.1-54, 7.79.1-53, 7.79.1-56, 8.4.0-35, 8.4.0-37
curl-doc - update to 8.4.0-26
libcurl-minimal - update to 8.4.0-26
libcurl-devel - update to 8.4.0-26
libcurl - update to 8.4.0-26
curl-minimal - update to 8.4.0-26
curl - update to 8.4.0-26
curl (Red Hat package) - update to 8.12.1-1.el10_0.10
curl - addressed in versions 8.15.0-8.fc43, 8.18.0-8.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Fedora 44 update for curl
- Fedora 43 update for curl
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Ubuntu update for curl
- openEuler 24.03 LTS SP3 update for curl
- openEuler 24.03 LTS SP1 update for curl
- openEuler 22.03 LTS SP4 update for curl
- openEuler 20.03 LTS SP4 update for curl
- openEuler 24.03 LTS SP4 update for curl
- Anolis OS update for curl
- openEuler 24.03 LTS SP4 update for curl
- openEuler 24.03 LTS SP3 update for curl
- openEuler 24.03 LTS SP1 update for curl
- openEuler 22.03 LTS SP4 update for curl
- openEuler 20.03 LTS SP4 update for curl
- Red Hat Enterprise Linux 10 update for curl