CVE-2026-13608
Description
A flaw was found in libcurl's SASL (Simple Authentication and Security Layer) negotiation for LDAP (Lightweight Directory Access Protocol) authentication when using the OpenLDAP backend. An incomplete handshake sequence can be misinterpreted as a successful cryptographic verification. A remote attacker, by performing a Man-in-the-Middle (MITM) attack, could inject a premature response to bypass complete peer validation, leading to an authentication bypass.
Statement
This Low impact flaw in libcurl's SASL negotiation for LDAP authentication could allow an attacker to bypass peer validation through a Man-in-the-Middle (MITM) attack. Exploitation requires an active network attacker to inject a premature response during the authentication handshake.
Mitigation
To mitigate enforce strict mutual authentication and cryptographic verification of both endpoints before transmitting sensitive data. Implement robust TLS/SSL configurations with explicit certificate pinning or strict CA validation to prevent Man-in-the-Middle (MITM) attackers from intercepting, prematurely concluding, or manipulating the handshake.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 3.7 | N/A | 7.4 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | High | N/A | High |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | Low | N/A | High |
| Integrity Impact | None | N/A | High |
| Availability Impact | None | N/A | None |
Vector
Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Understanding the Weakness (CWE)
Integrity,Confidentiality
Technical Impact: Gain Privileges or Assume Identity
If an attacker can spoof the endpoint, the attacker gains all the privileges that were intended for the original endpoint.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.