CVE-2026-8925
published 2026-07-03CVE-2026-8925: The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.08%
61.4th percentile
The curl logic that works with SASL authentication could end up cleaning up
the GSASL context *twice* without clearing the pointer in between, making it
`free()` the same pointer twice.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 8.15.0 – 8.15.0 | — |
| curl | curl | 8.16.0 – 8.16.0 | — |
| curl | curl | 8.17.0 – 8.17.0 | — |
| curl | curl | 8.18.0 – 8.18.0 | — |
| curl | curl | 8.19.0 – 8.19.0 | — |
| curl | curl | 8.20.0 – 8.20.0 | — |
| devspaces | code-rhel9 | — | — |
| haxx | curl | — | — |
| haxx | curl | >= 8.15.0 < 8.21.0 | 8.21.0 |
| rhtpa | rhtpa-trustification-service-rhel9 | — | — |
| rust-lang | rust | — | — |
| ubuntu | curl | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
ghsa_unreviewed·2026-07-03
CVE-2026-8925 The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
The curl logic that works with SASL authentication could end up cleaning up
the GSASL context *twice* without clearing the pointer in between, making it
`free()` the same pointer twice.
VulDB
cURL up to 8.20.0 free double free (EUVD-2026-41506)
vuldb·2026-07-03
CVE-2026-8925 [CRITICAL] cURL up to 8.20.0 free double free (EUVD-2026-41506)
A vulnerability labeled as critical has been found in cURL up to 8.20.0. Affected is the function free. Executing a manipulation can lead to double free.
This vulnerability appears as CVE-2026-8925. The attack may be performed from remote. There is no available exploit.
Red Hat
curl: curl: Double-free vulnerability in SASL authentication
vendor_redhat·2026-07-03·CVSS 9.8
CVE-2026-8925 [CRITICAL] CWE-1341 curl: curl: Double-free vulnerability in SASL authentication
curl: curl: Double-free vulnerability in SASL authentication
The curl logic that works with SASL authentication could end up cleaning up
the GSASL context *twice* without clearing the pointer in between, making it
`free()` the same pointer twice.
A flaw was found in curl. The logic handling SASL (Simple Authentication and Security Layer) authentication could lead to a double-free vulnerability. This occurs because the GSASL context may be deallocated twice without clearing the pointer, potentially leading to memory corruption. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.
Statement: This Important flaw in curl's SASL authentication logic could lead to a double-free vulnerability, potentially resulting in memory corruption, denial of s
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-06-30
CVE-2026-8286 curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Andrew Nesbitt discovered that curl could reuse an existing live
connection during STARTTLS-based connection upgrades even when the TLS
configuration did not match. A remote attacker could possibly use this
issue to cause curl to use an unintended TLS configuration.
(CVE-2026-8286)
Muhamad Arga Reksapati discovered that curl incorrectly reused
connections for Negotiate-authenticated requests when different services
were involved. A remote attacker could possibly use this issue to access
resources authenticated for another service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458)
It was discovered that curl i
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-8925 rpi-imager: curl: Double-free vulnerability in SASL authentication [fedora-all]
bugzilla·2026-07-06·CVSS 9.8
CVE-2026-8925 [CRITICAL] CVE-2026-8925 rpi-imager: curl: Double-free vulnerability in SASL authentication [fedora-all]
CVE-2026-8925 rpi-imager: curl: Double-free vulnerability in SASL authentication [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The curl logic that works with SASL authentication could end up cleaning up
the GSASL context *twice* without clearing the pointer in between, making it
`free()` the same pointer twice.
Bugzilla
CVE-2026-8925 mingw-curl: curl: Double-free vulnerability in SASL authentication [fedora-all]
bugzilla·2026-07-06·CVSS 9.8
CVE-2026-8925 [CRITICAL] CVE-2026-8925 mingw-curl: curl: Double-free vulnerability in SASL authentication [fedora-all]
CVE-2026-8925 mingw-curl: curl: Double-free vulnerability in SASL authentication [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The curl logic that works with SASL authentication could end up cleaning up
the GSASL context *twice* without clearing the pointer in between, making it
`free()` the same pointer twice.
Bugzilla
CVE-2026-8925 curl: curl: Double-free vulnerability in SASL authentication [fedora-all]
bugzilla·2026-07-06·CVSS 9.8
CVE-2026-8925 [CRITICAL] CVE-2026-8925 curl: curl: Double-free vulnerability in SASL authentication [fedora-all]
CVE-2026-8925 curl: curl: Double-free vulnerability in SASL authentication [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The curl logic that works with SASL authentication could end up cleaning up
the GSASL context *twice* without clearing the pointer in between, making it
`free()` the same pointer twice.
Bugzilla
CVE-2026-8925 curl: curl: Double-free vulnerability in SASL authentication
bugzilla·2026-07-03·CVSS 9.8
CVE-2026-8925 [CRITICAL] CVE-2026-8925 curl: curl: Double-free vulnerability in SASL authentication
CVE-2026-8925 curl: curl: Double-free vulnerability in SASL authentication
The curl logic that works with SASL authentication could end up cleaning up
the GSASL context *twice* without clearing the pointer in between, making it
`free()` the same pointer twice.
2026-07-03
Published