CVE-2026-11586
published 2026-07-03CVE-2026-11586: By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.86%
54.3th percentile
By default, curl automatically responds to WebSocket PING frames. Because curl
lacks an upper bound on memory allocation for unacknowledged frames, a
malicious server can exhaust all available memory by flooding curl with rapid,
sequential PING messages.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 8.16.0 – 8.16.0 | — |
| curl | curl | 8.17.0 – 8.17.0 | — |
| curl | curl | 8.18.0 – 8.18.0 | — |
| curl | curl | 8.19.0 – 8.19.0 | — |
| curl | curl | 8.20.0 – 8.20.0 | — |
| devspaces | code-rhel9 | — | — |
| haxx | curl | — | — |
| haxx | curl | >= 8.16.0 < 8.21.0 | 8.21.0 |
| rhtpa | rhtpa-trustification-service-rhel9 | — | — |
| rust-lang | rust | — | — |
| ubuntu | curl | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
vendor_ubuntu3.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
By default, curl automatically responds to WebSocket PING frames.
ghsa_unreviewed·2026-07-03
CVE-2026-11586 By default, curl automatically responds to WebSocket PING frames.
By default, curl automatically responds to WebSocket PING frames. Because curl
lacks an upper bound on memory allocation for unacknowledged frames, a
malicious server can exhaust all available memory by flooding curl with rapid,
sequential PING messages.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-07-09·CVSS 3.4
CVE-2026-11352 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Harry Sintonen discovered that curl incorrectly handled credentials when
following HTTP redirects in conjunction with .netrc files. An attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
(CVE-2024-11053)
Hiroki Kurosawa discovered that curl incorrectly handled OCSP stapling
responses. A remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2024-8096)
Joshua Rogers discovered that curl had a use-after-free vulnerability when
resetting and cleaning up HTTP/2 stream handles. An attacker could possibly
use this issue
Red Hat
curl: curl: Denial of Service via WebSocket PING flood
vendor_redhat·2026-07-03·CVSS 7.5
CVE-2026-11586 [HIGH] CWE-770 curl: curl: Denial of Service via WebSocket PING flood
curl: curl: Denial of Service via WebSocket PING flood
By default, curl automatically responds to WebSocket PING frames. Because curl
lacks an upper bound on memory allocation for unacknowledged frames, a
malicious server can exhaust all available memory by flooding curl with rapid,
sequential PING messages.
A flaw was found in curl. A malicious server can exploit this vulnerability by sending rapid, sequential WebSocket PING messages. Due to a lack of an upper bound on memory allocation for unacknowledged frames, curl can be forced to exhaust all available memory, leading to a denial of service.
Statement: This Important denial of service vulnerability in curl allows a remote malicious server to exhaust system memory. By default, curl automatically responds to WebSocket PING frames wit
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-11586 rpi-imager: curl: Denial of Service via WebSocket PING flood [fedora-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-11586 [HIGH] CVE-2026-11586 rpi-imager: curl: Denial of Service via WebSocket PING flood [fedora-all]
CVE-2026-11586 rpi-imager: curl: Denial of Service via WebSocket PING flood [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
By default, curl automatically responds to WebSocket PING frames. Because curl
lacks an upper bound on memory allocation for unacknowledged frames, a
malicious server can exhaust all available memory by flooding curl with rapid,
sequential PING messages.
Bugzilla
CVE-2026-11586 curl: curl: Denial of Service via WebSocket PING flood [fedora-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-11586 [HIGH] CVE-2026-11586 curl: curl: Denial of Service via WebSocket PING flood [fedora-all]
CVE-2026-11586 curl: curl: Denial of Service via WebSocket PING flood [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
By default, curl automatically responds to WebSocket PING frames. Because curl
lacks an upper bound on memory allocation for unacknowledged frames, a
malicious server can exhaust all available memory by flooding curl with rapid,
sequential PING messages.
Bugzilla
CVE-2026-11586 mingw-curl: curl: Denial of Service via WebSocket PING flood [fedora-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-11586 [HIGH] CVE-2026-11586 mingw-curl: curl: Denial of Service via WebSocket PING flood [fedora-all]
CVE-2026-11586 mingw-curl: curl: Denial of Service via WebSocket PING flood [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
By default, curl automatically responds to WebSocket PING frames. Because curl
lacks an upper bound on memory allocation for unacknowledged frames, a
malicious server can exhaust all available memory by flooding curl with rapid,
sequential PING messages.
Bugzilla
CVE-2026-11586 curl: curl: Denial of Service via WebSocket PING flood
bugzilla·2026-07-03·CVSS 7.5
CVE-2026-11586 [HIGH] CVE-2026-11586 curl: curl: Denial of Service via WebSocket PING flood
CVE-2026-11586 curl: curl: Denial of Service via WebSocket PING flood
By default, curl automatically responds to WebSocket PING frames. Because curl
lacks an upper bound on memory allocation for unacknowledged frames, a
malicious server can exhaust all available memory by flooding curl with rapid,
sequential PING messages.
2026-07-03
Published