Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13608

Опубликовано: 06 сент. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

A flaw was found in libcurl's SASL (Simple Authentication and Security Layer) negotiation for LDAP (Lightweight Directory Access Protocol) authentication when using the OpenLDAP backend. An incomplete handshake sequence can be misinterpreted as a successful cryptographic verification. A remote attacker, by performing a Man-in-the-Middle (MITM) attack, could inject a premature response to bypass complete peer validation, leading to an authentication bypass.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9Under investigation
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Under investigation
Red Hat Enterprise Linux 10curlUnder investigation
Red Hat Enterprise Linux 10igvmUnder investigation
Red Hat Enterprise Linux 10rustUnder investigation
Red Hat Enterprise Linux 10s390utilsUnder investigation
Red Hat Enterprise Linux 10snphostUnder investigation
Red Hat Enterprise Linux 10trusteeUnder investigation
Red Hat Enterprise Linux 6curlUnder investigation
Red Hat Enterprise Linux 7curlUnder investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2529198curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack

EPSS

Процентиль: 49%
0.00644
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
17 дней назад

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

CVSS3: 7.4
nvd
17 дней назад

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

msrc
16 дней назад

OpenLDAP SASL authentication bypass

CVSS3: 7.4
debian
17 дней назад

A flaw in the libcurl SASL negotiation for LDAP authentication allows ...

CVSS3: 7.4
github
17 дней назад

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

EPSS

Процентиль: 49%
0.00644
Низкий

3.7 Low

CVSS3