What happened
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
Affected versions
curl: 8.21.0 through 8.21.0 (semver); 8.20.0 through 8.20.0 (semver); 8.19.0 through 8.19.0 (semver); 8.18.0 through 8.18.0 (semver); 8.17.0 through 8.17.0 (semver); 8.16.0 through 8.16.0 (semver); 8.15.0 through 8.15.0 (semver); 8.14.1 through 8.14.1 (semver); 8.14.0 through 8.14.0 (semver); 8.13.0 through 8.13.0 (semver); 8.12.1 through 8.12.1 (semver); 8.12.0 through 8.12.0 (semver); 8.11.1 through 8.11.1 (semver); 8.11.0 through 8.11.0 (semver); 8.10.1 through 8.10.1 (semver); 8.10.0 through 8.10.0 (semver); 8.9.1 through 8.9.1 (semver); 8.9.0 through 8.9.0 (semver); 8.8.0 through 8.8.0 (semver); 8.7.1 through 8.7.1 (semver); 8.7.0 through 8.7.0 (semver); 8.6.0 through 8.6.0 (semver); 8.5.0 through 8.5.0 (semver); 8.4.0 through 8.4.0 (semver); 8.3.0 through 8.3.0 (semver); 8.2.1 through 8.2.1 (semver); 8.2.0 through 8.2.0 (semver); 8.1.2 through 8.1.2 (semver); 8.1.1 through 8.1.1 (semver); 8.1.0 through 8.1.0 (semver); 8.0.1 through 8.0.1 (semver); 8.0.0 through 8.0.0 (semver); 7.88.1 through 7.88.1 (semver); 7.88.0 through 7.88.0 (semver); 7.87.0 through 7.87.0 (semver); 7.86.0 through 7.86.0 (semver); 7.85.0 through 7.85.0 (semver); 7.84.0 through 7.84.0 (semver); 7.83.1 through 7.83.1 (semver); 7.83.0 through 7.83.0 (semver); 7.82.0 through 7.82.0 (semver) Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
No public PoC reference has passed the current publication threshold.