Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11586

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

A flaw was found in curl. A malicious server can exploit this vulnerability by sending rapid, sequential WebSocket PING messages. Due to a lack of an upper bound on memory allocation for unacknowledged frames, curl can be forced to exhaust all available memory, leading to a denial of service.

Отчет

This Important denial of service vulnerability in curl allows a remote malicious server to exhaust system memory. By default, curl automatically responds to WebSocket PING frames without an upper bound on memory allocation, enabling an attacker to trigger resource exhaustion and cause service unavailability in affected Red Hat products.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10curlAffected
Red Hat Enterprise Linux 6curlOut of support scope
Red Hat Enterprise Linux 7curlOut of support scope
Red Hat Enterprise Linux 8curlNot affected
Red Hat Enterprise Linux 9curlAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat OpenShift Dev Spacesdevspaces/code-rhel9Not affected
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Not affected
Red Hat Hardened Imagescurl-main-8.21.0-0.1.hum1FixedRHSA-2026:2901724.06.2026
Red Hat Hardened Imagesrust-main-1.96.1-1.hum1FixedRHSA-2026:3497502.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2496753curl: curl: Denial of Service via WebSocket PING flood

EPSS

Процентиль: 40%
0.00491
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

CVSS3: 7.5
nvd
около 1 месяца назад

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

CVSS3: 7.5
debian
около 1 месяца назад

By default, curl automatically responds to WebSocket PING frames. Beca ...

CVSS3: 7.5
github
около 1 месяца назад

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

CVSS3: 3.1
fstec
около 2 месяцев назад

Уязвимость компонента WebSocket библиотеки libcurl программного средства для взаимодействия с серверами cURL, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 40%
0.00491
Низкий

7.5 High

CVSS3