Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-11586

Опубликовано: 03 июл. 2026
Источник: ubuntu
Приоритет: low
CVSS3: 7.5

Описание

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

РелизСтатусПримечание
devel

pending

8.20.0-2ubuntu4
esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

not-affected

code not present
resolute

released

8.18.0-1ubuntu2.3
upstream

pending

8.21.0

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
3 месяца назад

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

CVSS3: 7.5
nvd
3 месяца назад

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

msrc
около 1 месяца назад

WS Auto-PONG memory exhaustion

CVSS3: 7.5
debian
3 месяца назад

By default, curl automatically responds to WebSocket PING frames. Beca ...

CVSS3: 7.5
github
3 месяца назад

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

7.5 High

CVSS3