A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
{
"URL": "https://curl.se/docs/CVE-2026-13608.json",
"CWE": {
"desc": "Improper Restriction of Communication Channel to Intended Endpoints",
"id": "CWE-923"
},
"package": "curl",
"affects": "both",
"last_affected": "8.21.0",
"www": "https://curl.se/docs/CVE-2026-13608.html",
"severity": "Low",
"issue": "https://hackerone.com/reports/3822248"
}[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"326639408536088429782387452173430813488",
"309793192306506390906797793866759243868",
"25094943265867132959496315694728531457",
"131351165008478471621245708616349825336",
"194811653429796140974907197863500476284"
],
"threshold": 0.9
},
"id": "CURL-CVE-2026-13608-2ddb3aa2",
"target": {
"file": "lib/openldap.c"
},
"source": "https://github.com/curl/curl.git/commit/ea71c3b6b60e563651ea8596a975aef0c8199519",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 713.0,
"function_hash": "241857058883287100469178053667771510182"
},
"id": "CURL-CVE-2026-13608-cc8eade8",
"target": {
"function": "oldap_state_sasl_resp",
"file": "lib/openldap.c"
},
"source": "https://github.com/curl/curl.git/commit/ea71c3b6b60e563651ea8596a975aef0c8199519",
"signature_version": "v1"
}
]
"https://curl.se/docs/CURL-CVE-2026-13608.json"
"2026-09-02T08:04:19Z"