CVE-2026-9080
published 2026-07-03CVE-2026-9080: Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store…
PriorityP340high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.49%
39.0th percentile
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`
callback triggers a use-after-free vulnerability, where libcurl attempts to
store a flag using a dangling struct pointer immediately after that pointer's
memory has been freed.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 8.13.0 – 8.13.0 | — |
| curl | curl | 8.14.0 – 8.14.0 | — |
| curl | curl | 8.14.1 – 8.14.1 | — |
| curl | curl | 8.15.0 – 8.15.0 | — |
| curl | curl | 8.16.0 – 8.16.0 | — |
| curl | curl | 8.17.0 – 8.17.0 | — |
| curl | curl | 8.18.0 – 8.18.0 | — |
| curl | curl | 8.19.0 – 8.19.0 | — |
| curl | curl | 8.20.0 – 8.20.0 | — |
| haxx | curl | — | — |
| haxx | curl | >= 8.13.0 < 8.21.0 | 8.21.0 |
| rust-lang | rust | — | — |
| ubuntu | curl | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer im
ghsa_unreviewed·2026-07-03
CVE-2026-9080 Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer im
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`
callback triggers a use-after-free vulnerability, where libcurl attempts to
store a flag using a dangling struct pointer immediately after that pointer's
memory has been freed.
VulDB
curl libcURL up to 8.20.0 curl_easy_pause use after free (EUVD-2026-41511 / WID-SEC-2026-2052)
vuldb·2026-07-03
CVE-2026-9080 [CRITICAL] curl libcURL up to 8.20.0 curl_easy_pause use after free (EUVD-2026-41511 / WID-SEC-2026-2052)
A vulnerability was found in curl libcURL up to 8.20.0. It has been rated as critical. The impacted element is the function curl_easy_pause. This manipulation causes use after free.
This vulnerability is registered as CVE-2026-9080. Remote exploitation of the attack is possible. No exploit is available.
Red Hat
libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback
vendor_redhat·2026-07-03·CVSS 7.3
CVE-2026-9080 [HIGH] CWE-825 libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback
libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`
callback triggers a use-after-free vulnerability, where libcurl attempts to
store a flag using a dangling struct pointer immediately after that pointer's
memory has been freed.
A flaw was found in libcurl. When `curl_easy_pause()` is called within the event-based `CURLMOPT_SOCKETFUNCTION` callback, a use-after-free vulnerability is triggered. This occurs because libcurl attempts to store a flag using a pointer to memory that has already been freed. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
Statement: This Important flaw in libcurl stems from a use-after-free vulnera
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-06-30
CVE-2026-8286 curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Andrew Nesbitt discovered that curl could reuse an existing live
connection during STARTTLS-based connection upgrades even when the TLS
configuration did not match. A remote attacker could possibly use this
issue to cause curl to use an unintended TLS configuration.
(CVE-2026-8286)
Muhamad Arga Reksapati discovered that curl incorrectly reused
connections for Negotiate-authenticated requests when different services
were involved. A remote attacker could possibly use this issue to access
resources authenticated for another service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458)
It was discovered that curl i
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-9080 davix: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback [epel-all]
bugzilla·2026-07-06·CVSS 7.3
CVE-2026-9080 [HIGH] CVE-2026-9080 davix: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback [epel-all]
CVE-2026-9080 davix: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`
callback triggers a use-after-free vulnerability, where libcurl attempts to
store a flag using a dangling struct pointer immediately after that pointer's
memory has been freed.
Bugzilla
CVE-2026-9080 libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback
bugzilla·2026-07-03·CVSS 7.3
CVE-2026-9080 [HIGH] CVE-2026-9080 libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback
CVE-2026-9080 libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`
callback triggers a use-after-free vulnerability, where libcurl attempts to
store a flag using a dangling struct pointer immediately after that pointer's
memory has been freed.
2026-07-03
Published