CVE-2026-11586

Name
CVE-2026-11586
Description
By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
2499f714-1537-4658-8207-48ae4bb9eae9 https://curl.se/docs/CVE-2026-11586.html
2499f714-1537-4658-8207-48ae4bb9eae9 https://curl.se/docs/CVE-2026-11586.json
2499f714-1537-4658-8207-48ae4bb9eae9 https://hackerone.com/reports/3788931

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* curl >= 8.16.0 < 8.21.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
curl edge-main 8.21.0-r0 Achill Gilgenast <achill@achill.org> fixed
curl edge-main 8.20.0-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.20.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.19.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.18.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.17.0-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.17.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.16.0-r2 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.16.0-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.16.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl 3.24-main 8.21.0-r0 Achill Gilgenast <achill@achill.org> fixed
curl 3.24-main 8.20.0-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl 3.23-main 8.19.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl 3.23-main 8.17.0-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable