CVE-2026-11586

curl vulnerabilities

Beschreibung

Standardmäßig reagiert curl automatisch auf WebSocket-PING-Frames. Da curl keine obere Grenze für den Speicherbedarf von nicht bestätigten Frames hat, kann ein böswilliger Server alle verfügbaren Speichermittel erschöpfen, indem er curl mit schnellen, sequentiellen PING-Nachrichten überschwemmt.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.5
Quelle: nvd-v3
47.2 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.6 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-09 19:14 UTC

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-07-06 16:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    • SSVC: {"id":"CVE-2026-11586","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  2. New CVE Received2026-07-03 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
    • Affected: curl
    • Description: By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.
    • Reference: https://curl.se/docs/CVE-2026-11586.html
    • Reference: https://curl.se/docs/CVE-2026-11586.json

Betroffene Betriebssysteme

  • linux

    ubuntu / curlbionic

  • linux

    ubuntu / curlfocal

  • linux

    ubuntu / curlnoble

  • linux

    ubuntu / curlquesting

  • linux

    ubuntu / curlresolute

  • linux

    ubuntu / curltrusty

  • linux

    ubuntu / curlxenial

  • linux

    debian / debian_linux11.0

  • other

    netapp / bootstrap_os

  • other

    netapp / h300s_firmware

  • other

    netapp / h410s_firmware

  • other

    netapp / h500s_firmware

  • other

    netapp / h610c_firmware

  • other

    netapp / h610s_firmware

  • other

    netapp / h615c_firmware

  • other

    netapp / h700s_firmware

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Splunk

    Splunk Enterprise< 10.0.9

    gefixt in 10.0.9

  • Splunk

    Splunk Enterprise< 10.2.6

    gefixt in 10.2.6

  • Splunk

    Splunk Enterprise< 10.4.2

    gefixt in 10.4.2

  • Splunk

    Splunk Enterprise< 9.4.14

    gefixt in 9.4.14

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-11586