PT-2026-51739 · Libcurl+3 · Libcurl+3

·

CVE-2026-10536

·

Published

2026-05-20

·

Updated

2026-08-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libcurl (affected versions not specified)
Description A use-after-free issue exists in libcurl involving the HTTP/2 stream-dependency tree management. This occurs when an application configures the tree using CURLOPT STREAM DEPENDS or CURLOPT STREAM DEPENDS E, calls the curl easy reset() function, and then terminates the handle via the curl easy cleanup() function. During the final cleanup, the library attempts to access and modify an internal structure that was already freed during the reset operation. This flaw may allow a remote attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91818
AZL-91839
BDU:2026-08696
CVE-2026-10536
ECHO-0D6F-7FBE-C7FA
JLSEC-2026-1197
OESA-2026-2986
OESA-2026-2987
OESA-2026-2988
OPENSUSE-SU-2026:11230-1
OPENSUSE-SU-2026:21272-1
RHSA-2026:41240
SUSE-SU-2026:22553-1
SUSE-SU-2026:22582-1
SUSE-SU-2026:22709-1
SUSE-SU-2026:22889-1
SUSE-SU-2026:2925-1
SUSE-SU-2026:2926-1
SUSE-SU-2026:3043-1
SUSE-SU-2026:3814-1
USN-8525-1

Affected Products

Ibm Aix
Linuxmint
Ubuntu
Libcurl