cbcvebase.
CVE-2026-3805
published 2026-03-11

CVE-2026-3805: When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.95%
59.6th percentile
When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

Affected

21 ranges
VendorProductVersion rangeFixed in
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl>= 8.13.0 < 8.14.28.14.2
curlcurl>= 8.15.0 < 8.16.18.16.1
curlcurl>= 8.17.0 < 8.19.08.19.0
curlcurl>= f4831daa9b2a97e8a2921d6b62cc4dfdd0d8646e < e090be9f73a7a71459ef678c7cc4b1f75e3ea883e090be9f73a7a71459ef678c7cc4b1f75e3ea883
debiancurl< curl 8.19.0-1 (forky)curl 8.19.0-1 (forky)
haxxcurl>= 0 < 8.19.0-18.19.0-1
haxxcurl>= 0 < 7.81.0-1ubuntu1.237.81.0-1ubuntu1.23
haxxcurl>= 0 < 8.5.0-2ubuntu10.88.5.0-2ubuntu10.8
haxxcurl>= 0 < 8.14.1-2ubuntu1.28.14.1-2ubuntu1.2
haxxcurl>= 8.13.0 < 8.19.08.19.0
msrcazl3_mysql_8.0.45-1_on_azure_linux_3.0——
msrcazl3_rust_1.75.0-25_on_azure_linux_3.0——
msrcazl3_rust_1.90.0-4_on_azure_linux_3.0——
msrccbl2_mysql_8.0.45-2_on_cbl_mariner_2.0——

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5LOW
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu3.4LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.