Improper restriction of communication channel to intended endpoints in cURL - CVE-2026-13608

 

Improper restriction of communication channel to intended endpoints in cURL - CVE-2026-13608

Published: September 2, 2026


Vulnerability identifier: #VU146685
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-13608
CWE-ID: CWE-923
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass LDAP server authentication.

The vulnerability exists due to improper restriction of communication channel to intended endpoints in the libcurl SASL negotiation for LDAP authentication when processing an incomplete OpenLDAP SASL handshake sequence. A remote attacker can inject a premature or shortcut response to bypass LDAP server authentication.

The issue only occurs when the OpenLDAP backend is used, and LDAPS is not affected.


Affected software

cURL

How to mitigate CVE-2026-13608

Install security update from vendor's website.

cURL - update to 8.22.0

External References

Related Security Bulletins