# CVE-2026-11586

## Summary

- **CVE ID:** CVE-2026-11586
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-770
- **Published:** Jul 3, 2026
- **Last Modified:** Sep 17, 2026

## Description

By default, curl automatically responds to WebSocket PING frames. Because curl
lacks an upper bound on memory allocation for unacknowledged frames, a
malicious server can exhaust all available memory by flooding curl with rapid,
sequential PING messages.

## Affected Products

- curl — curl (8.20.0)
- curl — curl (8.19.0)
- curl — curl (8.18.0)
- curl — curl (8.17.0)
- curl — curl (8.16.0)
- curl — curl (0b091328773c64e23f5c4739da74527093c6a5ab)

## References

- [CNA](https://curl.se/docs/CVE-2026-11586.json)
- [CNA](https://curl.se/docs/CVE-2026-11586.html)
- [CNA](https://hackerone.com/reports/3788931)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.61%
- **EPSS Percentile:** 47.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._