curl vulnerability

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

Published 6 Sep 2026Updated 6 Sep 20263 sources
CVSS 0.0

What happened

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

Affected versions

curl: 8.21.0 through 8.21.0 (semver); 8.20.0 through 8.20.0 (semver); 8.19.0 through 8.19.0 (semver); 8.18.0 through 8.18.0 (semver); 8.17.0 through 8.17.0 (semver); 8.16.0 through 8.16.0 (semver); 8.15.0 through 8.15.0 (semver); 8.14.1 through 8.14.1 (semver); 8.14.0 through 8.14.0 (semver); 8.13.0 through 8.13.0 (semver); 8.12.1 through 8.12.1 (semver); 8.12.0 through 8.12.0 (semver); 8.11.1 through 8.11.1 (semver); 8.11.0 through 8.11.0 (semver); 8.10.1 through 8.10.1 (semver); 8.10.0 through 8.10.0 (semver); 8.9.1 through 8.9.1 (semver); 8.9.0 through 8.9.0 (semver); 8.8.0 through 8.8.0 (semver); 8.7.1 through 8.7.1 (semver); 8.7.0 through 8.7.0 (semver); 8.6.0 through 8.6.0 (semver); 8.5.0 through 8.5.0 (semver); 8.4.0 through 8.4.0 (semver); 8.3.0 through 8.3.0 (semver); 8.2.1 through 8.2.1 (semver); 8.2.0 through 8.2.0 (semver); 8.1.2 through 8.1.2 (semver); 8.1.1 through 8.1.1 (semver); 8.1.0 through 8.1.0 (semver); 8.0.1 through 8.0.1 (semver); 8.0.0 through 8.0.0 (semver); 7.88.1 through 7.88.1 (semver); 7.88.0 through 7.88.0 (semver); 7.87.0 through 7.87.0 (semver); 7.86.0 through 7.86.0 (semver); 7.85.0 through 7.85.0 (semver); 7.84.0 through 7.84.0 (semver); 7.83.1 through 7.83.1 (semver); 7.83.0 through 7.83.0 (semver); 7.82.0 through 7.82.0 (semver) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.