Junglewise Threat Intelligence

CVE-2026-13608: libcurl SASL negotiation authentication bypass in LDAP

CVE-2026-13608 · Severity: high · CVSS 7.4 · Published 2026-09-06

Technologies: Curl. Vendors: Haxx.

Executive brief

libcurl is a widely-used networking library that handles secure communication, including LDAP directory authentication. This flaw allows attackers performing a man-in-the-middle attack to trick the LDAP authentication process into accepting an incomplete handshake as successful, bypassing peer validation and potentially gaining unauthorized access to LDAP-protected resources.

Technical details

A flaw in the libcurl SASL negotiation mechanism for LDAP authentication (CWE-923: Improper Restriction of Communication Channel) allows an incomplete handshake sequence to be misinterpreted as successful cryptographic verification. An attacker performing a man-in-the-middle attack can inject a premature or shortcut response to bypass complete peer validation. The vulnerability only affects unencrypted LDAP:// connections using the OpenLDAP backend; LDAPS:// (LDAP over TLS) is not vulnerable as server certificate validation already prevents impostor attacks. The flaw was introduced in version 7.82.0 and fixed in versions 8.14.2, 8.16.1, 8.20.1, and 8.22.0 respectively across affected release branches.

Affected products

  • curl curl 7.82.0 to 8.21.0 (across multiple release branches; see advisory for affected version ranges)

Timeline

  • 2026-06-24: disclosed: Vulnerability reported to curl project
  • 2026-09-02: patched: curl 8.22.0 released with fix, coordinated with advisory publication
  • 2026-09-02: advisory: Security advisory published

References

Related threats