CVE-2026-13608: OpenLDAP SASL authentication bypass
Published Sep 6, 2026
·Updated
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
Affected Software
4 affected componentsFixes available
OpenLDAP SASL authentication
libcurl SASL negotiation
haxx curl>=7.82.0<8.22.0
debian/curl<=7.88.1-10+deb12u15, <=7.88.1-10+deb12u5, <=8.14.1-2+deb13u5
8.22.0-18.23.0~rc1-2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 8.22.0-1Fixed in 8.23.0~rc1-2
Event History
Sep 6, 2026
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 8, 2026
Data Sourced
via Microsoft·08:03 AM
DescriptionSeverityWeakness
Sep 24, 2026
Data Sourced
via Debian·09:12 PM
DescriptionAffected Software
Data Sourced
via Launchpad·09:12 PM
Description
Sep 26, 2026
Data Sourced
via Ubuntu·09:12 PM
RemedyDescriptionSeverityAffected Software