Beveiligingsadvies

CVE-2026-11586

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-03 06:13:04
Laatst bijgewerkt 2026-09-15 06:02:41
Toegewezen door curl
CVSS-score 7.5
Status PUBLISHED

Beschrijving

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.