cbcvebase.
CVE-2026-10536
published 2026-07-03

CVE-2026-10536: A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or…

PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.89%
55.5th percentile
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
curlcurl7.88.0 – 7.88.0
curlcurl7.88.1 – 7.88.1
curlcurl8.0.0 – 8.0.0
curlcurl8.0.1 – 8.0.1
curlcurl8.1.0 – 8.1.0
curlcurl8.1.1 – 8.1.1
curlcurl8.1.2 – 8.1.2
curlcurl8.10.0 – 8.10.0
curlcurl8.10.1 – 8.10.1
curlcurl8.11.0 – 8.11.0
curlcurl8.11.1 – 8.11.1
curlcurl8.12.0 – 8.12.0
curlcurl8.12.1 – 8.12.1
curlcurl8.13.0 – 8.13.0
curlcurl8.14.0 – 8.14.0
curlcurl8.14.1 – 8.14.1
curlcurl8.15.0 – 8.15.0
curlcurl8.16.0 – 8.16.0
curlcurl8.17.0 – 8.17.0
curlcurl8.18.0 – 8.18.0
curlcurl8.19.0 – 8.19.0
curlcurl8.2.0 – 8.2.0
curlcurl8.2.1 – 8.2.1
curlcurl8.20.0 – 8.20.0
curlcurl8.3.0 – 8.3.0

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
vendor_ubuntu3.4LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.