CVE-2026-80229
published 2026-09-06CVE-2026-80229: When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.56%
44.9th percentile
When performing transfers via libcurl’s multi interface, pooled TLS
connections can outlive their originating easy handles. In OpenSSL 3 provider
configurations, libcurl attaches an allocated library context to the easy
handle's state and passes it to OpenSSL without acquiring an ownership
reference; destroying the easy handle prematurely frees this context while the
active connection retains a dangling pointer, leading to a heap-use-after-free
upon subsequent I/O or post-handshake operations.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | >= 8.14.0 < 8.14.2 | 8.14.2 |
| curl | curl | >= 8.15.0 < 8.16.1 | 8.16.1 |
| curl | curl | >= 8.17.0 < 8.20.1 | 8.20.1 |
| curl | curl | >= 8.21.0 < 8.22.0 | 8.22.0 |
| curl | curl | >= f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 < 7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb | 7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb |
| haxx | curl | >= 8.14.0 < 8.22.0 | 8.22.0 |
| ubuntu | curl | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
curl libcurl up to 8.21.0 Multi Interface use after free (EUVD-2026-72167)
vuldb·2026-09-06
CVE-2026-80229 [CRITICAL] curl libcurl up to 8.21.0 Multi Interface use after free (EUVD-2026-72167)
A vulnerability was found in curl libcurl up to 8.21.0. It has been classified as critical. This affects an unknown part of the component Multi Interface. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2026-80229. The attack is possible to be carried out remotely. No exploit exists.
GHSA
When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles.
ghsa_unreviewed·2026-09-06
CVE-2026-80229 When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles.
When performing transfers via libcurl’s multi interface, pooled TLS
connections can outlive their originating easy handles. In OpenSSL 3 provider
configurations, libcurl attaches an allocated library context to the easy
handle's state and passes it to OpenSSL without acquiring an ownership
reference; destroying the easy handle prematurely frees this context while the
active connection retains a dangling pointer, leading to a heap-use-after-free
upon subsequent I/O or post-handshake operations.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-09-24·CVSS 7.4
CVE-2026-80229 [HIGH] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for
LDAP authentication in certain circumstances. A machine-in-the-middle
attacker could possibly use this issue to bypass peer validation. This
issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-13608)
Stephan Zeisberg discovered that curl incorrectly handled HTTP/2 Server
Push streams when sharing connections between handles. A remote attacker
could possibly use this issue to cause curl to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2026-18924)
Stanislav Fort discovered that curl incorrectly managed the lifetime of
pooled TLS connections when using the multi interface. An attacker could
pos
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-80229 curl: libcurl: Memory corruption vulnerability via OpenSSL 3 provider use-after-free [fedora-all]
bugzilla·2026-09-21·CVSS 7.5
CVE-2026-80229 [HIGH] CVE-2026-80229 curl: libcurl: Memory corruption vulnerability via OpenSSL 3 provider use-after-free [fedora-all]
CVE-2026-80229 curl: libcurl: Memory corruption vulnerability via OpenSSL 3 provider use-after-free [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When performing transfers via libcurl’s multi interface, pooled TLS
connections can outlive their originating easy handles. In OpenSSL 3 provider
configurations, libcurl attaches an allocated library context to the easy
handle's state and passes it to OpenSSL without acquiring an ownership
reference; destroying the easy handle prematurely frees this context while the
active connection retains a dangling pointer, leading to a heap-use-after-free
upon subsequ
Bugzilla
CVE-2026-80229 mingw-curl: libcurl: Memory corruption vulnerability via OpenSSL 3 provider use-after-free [fedora-all]
bugzilla·2026-09-21·CVSS 7.5
CVE-2026-80229 [HIGH] CVE-2026-80229 mingw-curl: libcurl: Memory corruption vulnerability via OpenSSL 3 provider use-after-free [fedora-all]
CVE-2026-80229 mingw-curl: libcurl: Memory corruption vulnerability via OpenSSL 3 provider use-after-free [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When performing transfers via libcurl’s multi interface, pooled TLS
connections can outlive their originating easy handles. In OpenSSL 3 provider
configurations, libcurl attaches an allocated library context to the easy
handle's state and passes it to OpenSSL without acquiring an ownership
reference; destroying the easy handle prematurely frees this context while the
active connection retains a dangling pointer, leading to a heap-use-after-free
upon s
2026-09-06
Published