news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-11586

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
7.5 High
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Risk score
60.0
Published
2026-07-03
Status
Published

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.

Weaknesses

CWE-770 Allocation of Resources Without Limits or Throttling

Coverage 1

Advisories and references