Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-18924

Опубликовано: 06 сент. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 9.1

Описание

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

РелизСтатусПримечание
devel

needed

esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

needed

esm-infra/bionic

needed

esm-infra/focal

needed

jammy

needed

noble

needed

resolute

needed

upstream

released

8.22.0~rc2-1

Показывать по

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
15 дней назад

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

CVSS3: 9.1
nvd
14 дней назад

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

msrc
12 дней назад

HTTP/2 server push UAF

CVSS3: 9.1
debian
14 дней назад

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the p ...

CVSS3: 9.1
github
14 дней назад

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

9.1 Critical

CVSS3