Impact
A flaw in libcurl’s SASL negotiation logic allows an attacker performing a man‑in‑the‑middle attack to inject a premature or shortcut response that the client interprets as a successful cryptographic verification. The incomplete handshake is thus treated as a valid authentication, enabling the attacker to bypass authentication controls and gain unauthorized access or impersonate a legitimate LDAP client.
Affected Systems
The vulnerability exists in the libcurl component used by the curl library. Devices or applications that rely on libcurl for LDAP authentication, particularly those enabling SASL negotiation, are at risk. Specific affected versions are not listed in the advisory, but any instance of libcurl that implements the vulnerable SASL code path is potentially impacted.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, so the overall exploitation probability cannot be quantified from these metrics. Nonetheless, the flaw permits a complete bypass of authentication once a MITM position is achieved, meaning that an attacker who can intercept or influence the LDAP traffic can achieve remote unauthenticated access. No public exploit is reported, but the attack path requires network-level access to mediate the handshake.
OpenCVE Enrichment