Intel

AIKIDO-2026-329787

libcurl is vulnerable to Double Free

Double FreeCVE-2026-8925 Published 6 days ago

55

Medium Risk

This Affects:

C++libcurl
8.15.0 - 8.20.0
Fixed in 8.21.0
Are you affected? Scan for Free

TL;DR

SASL authentication with GSASL frees the GSASL context twice and does not clear the pointer between the two frees. The second free() releases the same heap address again and corrupts the heap, which typically crashes the process. The fix clears the pointer after the first free.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your build uses GSASL for SASL authentication.

Background info

libcurl is vulnerable to Double Free in versions 8.15.0 - 8.20.0.

How to fix this

Upgrade the libcurl and/or the curl.curl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform