Intel

AIKIDO-2026-157711

libcurl is vulnerable to Authentication Bypass

Authentication BypassCVE-2026-13608 Published 6 days ago

37

Low Risk

This Affects:

C++libcurl
7.82.0 - 8.21.0
Fixed in 8.22.0
Are you affected? Scan for Free

TL;DR

LDAP SASL authentication accepts an unfinished handshake as a completed cryptographic check. A peer that can modify the connection can inject a short response and skip the rest of peer validation, so the client accepts the LDAP peer without a finished SASL exchange. The fix requires the handshake to finish before it reports success.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use LDAP with SASL authentication.

Background info

libcurl is vulnerable to Authentication Bypass in versions 7.82.0 - 8.21.0.

How to fix this

Upgrade the libcurl and/or the curl.curl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform