{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-11586","assignerOrgId":"2499f714-1537-4658-8207-48ae4bb9eae9","state":"PUBLISHED","assignerShortName":"curl","dateReserved":"2026-06-08T12:17:42.037Z","datePublished":"2026-07-03T06:13:04.448Z","dateUpdated":"2026-09-15T06:02:41.195Z"},"containers":{"cna":{"providerMetadata":{"orgId":"2499f714-1537-4658-8207-48ae4bb9eae9","shortName":"curl","dateUpdated":"2026-09-15T06:02:41.195Z"},"title":"WS Auto-PONG memory exhaustion","descriptions":[{"lang":"en","value":"By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages."}],"affected":[{"vendor":"curl","product":"curl","versions":[{"version":"8.16.0","status":"affected","versionType":"semver","lessThan":"8.16.1"},{"version":"8.17.0","status":"affected","versionType":"semver","lessThan":"8.20.1"}],"defaultStatus":"unaffected"},{"vendor":"curl","product":"curl","versions":[{"version":"0b091328773c64e23f5c4739da74527093c6a5ab","status":"affected","versionType":"git","lessThan":"849317ff5c5a5e13f50ec3d001e46ddffa77d8a4"}],"defaultStatus":"unaffected","repo":"https://github.com/curl/curl.git"},{"vendor":"curl","product":"curl","versions":[{"version":"8.20.0","status":"affected"},{"version":"8.19.0","status":"affected"},{"version":"8.18.0","status":"affected"},{"version":"8.17.0","status":"affected"},{"version":"8.16.0","status":"affected"}],"defaultStatus":"unaffected"}],"references":[{"url":"https://curl.se/docs/CVE-2026-11586.json"},{"url":"https://curl.se/docs/CVE-2026-11586.html"},{"url":"https://hackerone.com/reports/3788931"}],"x_osv":{"schema_version":"1.5.0","id":"CURL-CVE-2026-11586","aliases":["CVE-2026-11586"],"summary":"WS Auto-PONG memory exhaustion","modified":"2026-09-07T10:34:51.00Z","database_specific":{"package":"curl","affects":"both","URL":"https://curl.se/docs/CVE-2026-11586.json","www":"https://curl.se/docs/CVE-2026-11586.html","issue":"https://hackerone.com/reports/3788931","CWE":{"id":"CWE-770","desc":"Allocation of Resources Without Limits or Throttling"},"last_affected":"8.20.0","severity":"Low"},"published":"2026-06-24T08:00:00.00Z","affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"8.16.0"},{"fixed":"8.16.1"},{"introduced":"8.17.0"},{"fixed":"8.20.1"}]},{"type":"GIT","repo":"https://github.com/curl/curl.git","events":[{"introduced":"0b091328773c64e23f5c4739da74527093c6a5ab"},{"fixed":"849317ff5c5a5e13f50ec3d001e46ddffa77d8a4"}]}],"versions":["8.20.0","8.19.0","8.18.0","8.17.0","8.16.0"]}],"credits":[{"name":"evergarden1123 on hackerone (AntAISecurityLab)","type":"finder"},{"name":"Stefan Eissing","type":"remediation developer"}],"details":"By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages."},"problemTypes":[{"descriptions":[{"lang":"en","description":"Allocation of Resources Without Limits or Throttling","cweId":"CWE-770","type":"CWE"}]}],"credits":[{"lang":"en","value":"evergarden1123 on hackerone (AntAISecurityLab)","type":"finder"},{"lang":"en","value":"Stefan Eissing","type":"remediation developer"}],"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.5,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-07-06T15:16:22.568075Z","id":"CVE-2026-11586","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-06T15:16:27.052Z"}}]}}