Improper restriction of communication channel to intended endpoints in cURL - CVE-2026-13608
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass LDAP server authentication.
The vulnerability exists due to improper restriction of communication channel to intended endpoints in the libcurl SASL negotiation for LDAP authentication when processing an incomplete OpenLDAP SASL handshake sequence. A remote attacker can inject a premature or shortcut response to bypass LDAP server authentication.
The issue only occurs when the OpenLDAP backend is used, and LDAPS is not affected.