Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-13608

Опубликовано: 06 сент. 2026
Источник: debian
EPSS Низкий

Описание

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed8.22.0~rc2-1package
curlno-dsatrixiepackage
curlpostponedbookwormpackage

Примечания

  • https://curl.se/docs/CVE-2026-13608.html

  • Introduced with: https://github.com/curl/curl/commit/eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4 (curl-7_82_0)

  • Fixed by: https://github.com/curl/curl/commit/ea71c3b6b60e563651ea8596a975aef0c8199519 (rc-8_22_0-1)

EPSS

Процентиль: 49%
0.00644
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
17 дней назад

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

CVSS3: 3.7
redhat
17 дней назад

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

CVSS3: 7.4
nvd
17 дней назад

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

msrc
16 дней назад

OpenLDAP SASL authentication bypass

CVSS3: 7.4
github
17 дней назад

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

EPSS

Процентиль: 49%
0.00644
Низкий