CVE-2026-11586

Aliases:DEBIAN-CVE-2026-11586ALPINE-CVE-2026-11586CGA-28g6-7f33-cr6qCGA-43r9-cjv4-hwvgCGA-5j59-hgrh-98c6CGA-64gh-vqw8-vcg3CGA-6q5f-7h52-qx55CGA-8489-c66r-v2qwCGA-8mr2-r5rq-2xv7CGA-8r29-2cv6-r628CGA-8vjh-c89g-3m3fCGA-9jrc-8fv9-9m4hCGA-9m8c-48ch-628xCGA-c642-7pjp-2fvcCGA-g2c8-5xfh-j3mrCGA-hp7q-jmpw-5529CGA-jhjw-23h9-6jh2CGA-m5fm-8rhh-hpm6CGA-mqvq-3rf2-7qf9CGA-p368-wxjx-j5c5CGA-x3fg-v6qp-7rqmCGA-xgm7-r66p-mv8g
Modified
Published: 03 Jul 2026, 06:13
Last modified:15 Sept 2026, 06:02

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.61% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

03 Jul 2026, 06:13
Published
Vulnerability first disclosed
15 Sept 2026, 06:02
Last Modified
Vulnerability information updated

Description

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.61% Percentile: 48%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • alpinecurl

    ≥ 8.16.0, < 8.22.0-r0 | ≥ 8.16.0, < 8.21.0-r0

  • chainguardeco-python-curl

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal-bin

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal-dev

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal-doc

    < 8.21.0-r0

  • chainguardeco-python-curl-minimal-static

    < 8.21.0-r0

  • chainguardeco-python-curl-nghttp2

    < 8.21.0-r0

  • chainguardeco-python-curl-nghttp2-bin

    < 8.21.0-r0

  • chainguardeco-python-curl-nghttp2-dev

    < 8.21.0-r0

  • chainguardeco-python-curl-nghttp2-static

    < 8.21.0-r0

  • curlcurl

    8.20.0 | 8.19.0 | 8.18.0 | 8.17.0 | 8.16.0 | ≥ 8.16.0, < 8.16.1 | ≥ 8.17.0, < 8.20.1 | ≥ 0b091328773c64e23f5c4739da74527093c6a5ab, < 849317ff5c5a5e13f50ec3d001e46ddffa77d8a4 | 8.20.0 | 8.19.0 | 8.18.0 | 8.17.0 | 8.16.0

  • debiancurl

    < 8.21.0~rc3-1

  • haxxcurl

    ≥ 8.16.0, < 8.21.0

References (7)