Executive brief
curl is a widely used tool and library for transferring data over various network protocols. A vulnerability in its WebSocket implementation allows a malicious server to crash the application or the entire system by flooding it with specific messages. This results in a denial-of-service condition where the software runs out of memory and stops functioning.
Technical details
A resource exhaustion vulnerability (CWE-770) exists in curl's WebSocket implementation. By default, curl automatically responds to WebSocket PING frames with PONG frames. However, the library lacks an upper bound on memory allocation for these unacknowledged outgoing frames. A malicious server can exploit this by sending a rapid sequence of PING messages, causing curl to allocate increasing amounts of memory until it or the host application crashes due to an out-of-memory (OOM) condition. The issue is fixed in version 8.21.0, and a workaround exists by disabling automatic PING responses using the CURLWS_NOAUTOPONG option.
Affected products
- curl curl 8.16.0 to 8.20.0
Timeline
- 2026-06-08: disclosed: Reported to curl project via HackerOne
- 2026-06-24: patched: Fixed in curl version 8.21.0
- 2026-06-24: advisory: Project advisory published