cbcvebase.
CVE-2026-80229
published 2026-09-06

CVE-2026-80229: When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.56%
44.9th percentile
When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations.

Affected

16 ranges
VendorProductVersion rangeFixed in
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl>= 8.14.0 < 8.14.28.14.2
curlcurl>= 8.15.0 < 8.16.18.16.1
curlcurl>= 8.17.0 < 8.20.18.20.1
curlcurl>= 8.21.0 < 8.22.08.22.0
curlcurl>= f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 < 7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb
haxxcurl>= 8.14.0 < 8.22.08.22.0
ubuntucurl——

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.