CVE-2026-18924
published 2026-09-06CVE-2026-18924: A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free…
PriorityP345critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.58%
46.1th percentile
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Affected
114 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| build-of-trustee | trustee-rhel9 | — | — |
| confidential-containers | trustee | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
vendor_redhat9.1CRITICAL
vendor_ubuntu7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-09-24·CVSS 7.4
CVE-2026-80229 [HIGH] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for
LDAP authentication in certain circumstances. A machine-in-the-middle
attacker could possibly use this issue to bypass peer validation. This
issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-13608)
Stephan Zeisberg discovered that curl incorrectly handled HTTP/2 Server
Push streams when sharing connections between handles. A remote attacker
could possibly use this issue to cause curl to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2026-18924)
Stanislav Fort discovered that curl incorrectly managed the lifetime of
pooled TLS connections when using the multi interface. An attacker could
pos
Red Hat
curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections
vendor_redhat·2026-09-06·CVSS 9.1
CVE-2026-18924 [CRITICAL] CWE-416 curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections
curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
A flaw was found in libcurl. When libcurl handles HTTP/2 Server Push streams and the parent handle shares connections, a use-after-free vulnerability can occur during the cleanup process. This could lead to application crashes, resulting in a denial of service.
Statement: This flaw is rated as Low impact. It affects libcurl when configured to use HTTP/2 Server Push with shared connections, a non-default and less common deployment scenario in Red Hat products. Successful exploitation would lead to a use-after-free condition during res
GHSA
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.
ghsa_unreviewed·2026-09-06
CVE-2026-18924 A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
VulDB
curl libcurl up to 8.21.0 HTTP/2 Server Push use after free (EUVD-2026-72165)
vuldb·2026-09-06
CVE-2026-18924 [CRITICAL] curl libcurl up to 8.21.0 HTTP/2 Server Push use after free (EUVD-2026-72165)
A vulnerability classified as critical was found in curl libcurl. Affected by this vulnerability is an unknown functionality of the component HTTP2 Server Push. Such manipulation leads to use after free.
This vulnerability is documented as CVE-2026-18924. The attack can be executed remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-18924 curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
bugzilla·2026-09-17·CVSS 9.1
CVE-2026-18924 [CRITICAL] CVE-2026-18924 curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
CVE-2026-18924 curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Bugzilla
CVE-2026-18924 stgit: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
bugzilla·2026-09-17·CVSS 9.1
CVE-2026-18924 [CRITICAL] CVE-2026-18924 stgit: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
CVE-2026-18924 stgit: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Discussion:
This package dynamically links system-provided libcurl, and does not include code from curl itself.
So the issue needs to be fixed in curl, and nothing can be done here.
Bugzilla
CVE-2026-18924 trustee-guest-components: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
bugzilla·2026-09-17·CVSS 9.1
CVE-2026-18924 [CRITICAL] CVE-2026-18924 trustee-guest-components: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
CVE-2026-18924 trustee-guest-components: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Bugzilla
CVE-2026-18924 nushell: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [epel-all]
bugzilla·2026-09-17·CVSS 9.1
CVE-2026-18924 [CRITICAL] CVE-2026-18924 nushell: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [epel-all]
CVE-2026-18924 nushell: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Discussion:
This package dynamically links system-provided libcurl, and does not include code from curl itself.
So the issue needs to be fixed in curl, and nothing can be done here.
Bugzilla
CVE-2026-18924 mingw-curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
bugzilla·2026-09-17·CVSS 9.1
CVE-2026-18924 [CRITICAL] CVE-2026-18924 mingw-curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
CVE-2026-18924 mingw-curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Bugzilla
CVE-2026-18924 rust: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
bugzilla·2026-09-17·CVSS 9.1
CVE-2026-18924 [CRITICAL] CVE-2026-18924 rust: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
CVE-2026-18924 rust: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Discussion:
The bundled `curl` sources (via the Rust `curl-sys` crate) are wholly removed during the `%prep` phase to be sure we don't use them. Instead, we use the system `curl` library, so any CVE fixes only need to be made in that component on its own.
Bugzilla
CVE-2026-18924 rpi-imager: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
bugzilla·2026-09-17·CVSS 9.1
CVE-2026-18924 [CRITICAL] CVE-2026-18924 rpi-imager: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
CVE-2026-18924 rpi-imager: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Bugzilla
CVE-2026-18924 nushell: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
bugzilla·2026-09-17·CVSS 9.1
CVE-2026-18924 [CRITICAL] CVE-2026-18924 nushell: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
CVE-2026-18924 nushell: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Discussion:
This package dynamically links system-provided libcurl, and does not include code from curl itself.
So the issue needs to be fixed in curl, and nothing can be done here.
Bugzilla
CVE-2026-18924 rustup: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
bugzilla·2026-09-17·CVSS 9.1
CVE-2026-18924 [CRITICAL] CVE-2026-18924 rustup: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
CVE-2026-18924 rustup: libcurl: Use-after-free in HTTP/2 Server Push with shared connections [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Discussion:
This package dynamically links system-provided libcurl, and does not include code from curl itself.
So the issue needs to be fixed in curl, and nothing can be done here.
Bugzilla
CVE-2026-18924 curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections
bugzilla·2026-09-06·CVSS 9.1
CVE-2026-18924 [CRITICAL] CVE-2026-18924 curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections
CVE-2026-18924 curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Rapid7
Patch Tuesday - September 2026
blogs_rapid7·2026-09-08·CVSS 7.8
CVE-2026-85880 [HIGH] Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today.
## Windows ALPC: zero-day EoP
The eternal game of elevation of privilege whack-a-mole between Microsoft and attackers continues. This month, the batt
2026-09-06
Published