September 4, 2026
- curl disclosed a large batch of HackerOne reports, several with real exploitation relevance: an OpenLDAP SASL flaw letting a malicious server bypass authentication and inject LDAP responses (CVE-2026-13608), a pinned-key validation bypass with anonymous ciphers and
--insecure(CVE-2026-80230), plus cookie-parsing bugs that storeSecurecookies insecurely and Windows Negotiate connection reuse with the wrong ambient credentials. · Exploitation & Vulnerabilities