CVE-2026-11586EPSS p40.0%
CVE-2026-11586CVE-2026-11586
haxx / curl
Description
By default, curl automatically responds to WebSocket PING frames. Because curl
lacks an upper bound on memory allocation for unacknowledged frames, a
malicious server can exhaust all available memory by flooding curl with rapid,
sequential PING messages.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.49% probability of exploitation · percentile 40.0% · 2026-08-17T12:03:47Z |
| Last modified | 2026-07-07 |