SASL Negotiation Flaw in libcurl Affects LDAP Authentication
CVE-2026-13608

Currently unrated

Key Information:

Vendor

Curl

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-13608?

A vulnerability exists in the SASL negotiation process of libcurl, where an incomplete handshake during LDAP authentication can mistakenly be treated as valid verification. This flaw could be exploited by attackers conducting Man-in-the-Middle (MITM) attacks, enabling them to inject responses that circumvent proper peer validation, potentially leading to unauthorized access or data manipulation.

Affected Version(s)

curl 8.21.0

curl 8.20.0

curl 8.19.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eunsoo Kim (Autonomous Code Security team at Microsoft)
Eunsoo Kim
.