A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
{
"CWE": {
"desc": "Improper Restriction of Communication Channel to Intended Endpoints",
"id": "CWE-923"
},
"URL": "https://curl.se/docs/CVE-2026-13608.json",
"affects": "both",
"issue": "https://hackerone.com/reports/3822248",
"last_affected": "8.21.0",
"package": "curl",
"severity": "Low",
"www": "https://curl.se/docs/CVE-2026-13608.html"
}"https://curl.se/docs/CURL-CVE-2026-13608.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"326639408536088429782387452173430813488",
"309793192306506390906797793866759243868",
"25094943265867132959496315694728531457",
"131351165008478471621245708616349825336",
"194811653429796140974907197863500476284"
],
"threshold": 0.9
},
"id": "CURL-CVE-2026-13608-2ddb3aa2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/curl/curl.git/commit/ea71c3b6b60e563651ea8596a975aef0c8199519",
"target": {
"file": "lib/openldap.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "241857058883287100469178053667771510182",
"length": 713
},
"id": "CURL-CVE-2026-13608-cc8eade8",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/curl/curl.git/commit/ea71c3b6b60e563651ea8596a975aef0c8199519",
"target": {
"file": "lib/openldap.c",
"function": "oldap_state_sasl_resp"
}
}
]
"2026-09-07T14:06:31Z"