libcurl is vulnerable to Use After Free
37
Low Risk
An application that builds an HTTP/2 stream dependency tree with CURLOPT_STREAM_DEPENDS or CURLOPT_STREAM_DEPENDS_E, then calls curl_easy_reset() and curl_easy_cleanup(), hits a use-after-free. Cleanup writes through a structure that reset already freed, which can crash the process or corrupt memory. The fix removes stream dependency tracking.
You are affected if you are using a version that falls within the vulnerable range and you set HTTP/2 stream dependencies and then reset the easy handle.
libcurl is vulnerable to Use After Free in versions 7.88.0 - 8.20.0.
Upgrade the libcurl and/or the curl.curl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.