CVE-2026-13608
CVE-2026-13608 is a high-severity vulnerability in Haxx Curl with a CVSS 3.x base score of 7.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-923.
Key facts
- Severity: High (CVSS 3.x base score 7.4)
- EPSS exploit prediction: 0% (39th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-923
- Affected product: Haxx Curl
- Published:
- Last modified:
Description
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
Frequently asked questions
- What is CVE-2026-13608?
- A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
- How severe is CVE-2026-13608?
- CVE-2026-13608 has a CVSS 3.x base score of 7.4, rated high severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-13608 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (39th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-13608?
- CVE-2026-13608 affects Haxx Curl. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-13608?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-13608 published?
- CVE-2026-13608 was published on 2026-09-06 and last updated on 2026-09-15.
References
- https://curl.se/docs/CVE-2026-13608.html
- https://curl.se/docs/CVE-2026-13608.json
- https://hackerone.com/reports/3822248
Affected products (1)
- cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
More vulnerabilities in Haxx Curl
- CVE-2026-19931 — Critical (CVSS 9.8): A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication,…
- CVE-2026-9079 — Critical (CVSS 9.8): libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the…
- CVE-2026-8925 — Critical (CVSS 9.8): The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing…
- CVE-2026-11856 — Critical (CVSS 9.8): Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then…
- CVE-2026-10536 — Critical (CVSS 9.8): A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via…
- CVE-2022-32221 — Critical (CVSS 9.8): When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data…
All CVEs affecting Haxx Curl →
Other CWE-923 vulnerabilities
- CVE-2019-17440 — Critical (CVSS 10.0): Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation…
- CVE-2024-41889 — Critical (CVSS 9.8): Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited,…
- CVE-2026-34205 — Critical (CVSS 9.6): Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps…
- CVE-2026-92173 — Critical (CVSS 9.1): Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent…
- CVE-2023-28078 — Critical (CVSS 9.1): Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A…
- CVE-2026-86345 — Critical (CVSS 9.0): A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection…