Intel

AIKIDO-2026-908514

libcurl is vulnerable to Use After Free

Use After FreeCVE-2026-10536 Published 6 days ago

37

Low Risk

This Affects:

C++libcurl
7.88.0 - 8.20.0
Fixed in 8.21.0
Are you affected? Scan for Free

TL;DR

An application that builds an HTTP/2 stream dependency tree with CURLOPT_STREAM_DEPENDS or CURLOPT_STREAM_DEPENDS_E, then calls curl_easy_reset() and curl_easy_cleanup(), hits a use-after-free. Cleanup writes through a structure that reset already freed, which can crash the process or corrupt memory. The fix removes stream dependency tracking.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you set HTTP/2 stream dependencies and then reset the easy handle.

Background info

libcurl is vulnerable to Use After Free in versions 7.88.0 - 8.20.0.

How to fix this

Upgrade the libcurl and/or the curl.curl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform