CVE-2026-11586

Published: July 2, 2026Last modified: July 6, 2026

Description

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTScurlFixed (8.21.0-r0)
25 LTScurlFixed (8.21.0-r0)
StreamcurlFixed (8.21.0-r0)
Hardened ContainersStreamcurlFixed (8.21.0-r0)

References

ON THIS PAGE