curl vulnerability

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

Published 6 Sep 2026Updated 6 Sep 20263 sources
CVSS 0.0

What happened

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

Affected versions

curl: 8.21.0 through 8.21.0 (semver); 8.20.0 through 8.20.0 (semver); 8.19.0 through 8.19.0 (semver); 8.18.0 through 8.18.0 (semver); 8.17.0 through 8.17.0 (semver); 8.16.0 through 8.16.0 (semver); 8.15.0 through 8.15.0 (semver); 8.14.1 through 8.14.1 (semver); 8.14.0 through 8.14.0 (semver); 8.13.0 through 8.13.0 (semver); 8.12.1 through 8.12.1 (semver); 8.12.0 through 8.12.0 (semver); 8.11.1 through 8.11.1 (semver); 8.11.0 through 8.11.0 (semver); 8.10.1 through 8.10.1 (semver); 8.10.0 through 8.10.0 (semver); 8.9.1 through 8.9.1 (semver); 8.9.0 through 8.9.0 (semver); 8.8.0 through 8.8.0 (semver); 8.7.1 through 8.7.1 (semver); 8.7.0 through 8.7.0 (semver); 8.6.0 through 8.6.0 (semver); 8.5.0 through 8.5.0 (semver); 8.4.0 through 8.4.0 (semver); 8.3.0 through 8.3.0 (semver); 8.2.1 through 8.2.1 (semver); 8.2.0 through 8.2.0 (semver); 8.1.2 through 8.1.2 (semver); 8.1.1 through 8.1.1 (semver); 8.1.0 through 8.1.0 (semver); 8.0.1 through 8.0.1 (semver); 8.0.0 through 8.0.0 (semver); 7.88.1 through 7.88.1 (semver); 7.88.0 through 7.88.0 (semver); 7.87.0 through 7.87.0 (semver); 7.86.0 through 7.86.0 (semver); 7.85.0 through 7.85.0 (semver); 7.84.0 through 7.84.0 (semver); 7.83.1 through 7.83.1 (semver); 7.83.0 through 7.83.0 (semver); 7.82.0 through 7.82.0 (semver); 7.81.0 through 7.81.0 (semver); 7.80.0 through 7.80.0 (semver); 7.79.1 through 7.79.1 (semver); 7.79.0 through 7.79.0 (semver); 7.78.0 through 7.78.0 (semver); 7.77.0 through 7.77.0 (semver); 7.76.1 through 7.76.1 (semver); 7.76.0 through 7.76.0 (semver); 7.75.0 through 7.75.0 (semver); 7.74.0 through 7.74.0 (semver); 7.73.0 through 7.73.0 (semver); 7.72.0 through 7.72.0 (semver); 7.71.1 through 7.71.1 (semver); 7.71.0 through 7.71.0 (semver); 7.70.0 through 7.70.0 (semver); 7.69.1 through 7.69.1 (semver); 7.69.0 through 7.69.0 (semver); 7.68.0 through 7.68.0 (semver); 7.67.0 through 7.67.0 (semver); 7.66.0 through 7.66.0 (semver); 7.65.3 through 7.65.3 (semver); 7.65.2 through 7.65.2 (semver); 7.65.1 through 7.65.1 (semver); 7.65.0 through 7.65.0 (semver); 7.64.1 through 7.64.1 (semver); 7.64.0 through 7.64.0 (semver); 7.63.0 through 7.63.0 (semver); 7.62.0 through 7.62.0 (semver); 7.61.1 through 7.61.1 (semver); 7.61.0 through 7.61.0 (semver); 7.60.0 through 7.60.0 (semver); 7.59.0 through 7.59.0 (semver); 7.58.0 through 7.58.0 (semver); 7.57.0 through 7.57.0 (semver); 7.56.1 through 7.56.1 (semver); 7.56.0 through 7.56.0 (semver); 7.55.1 through 7.55.1 (semver); 7.55.0 through 7.55.0 (semver); 7.54.1 through 7.54.1 (semver); 7.54.0 through 7.54.0 (semver); 7.53.1 through 7.53.1 (semver); 7.53.0 through 7.53.0 (semver); 7.52.1 through 7.52.1 (semver); 7.52.0 through 7.52.0 (semver); 7.51.0 through 7.51.0 (semver); 7.50.3 through 7.50.3 (semver); 7.50.2 through 7.50.2 (semver); 7.50.1 through 7.50.1 (semver); 7.50.0 through 7.50.0 (semver); 7.49.1 through 7.49.1 (semver); 7.49.0 through 7.49.0 (semver); 7.48.0 through 7.48.0 (semver); 7.47.1 through 7.47.1 (semver); 7.47.0 through 7.47.0 (semver); 7.46.0 through 7.46.0 (semver); 7.45.0 through 7.45.0 (semver); 7.44.0 through 7.44.0 (semver) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.