Количество 11
Количество 11
CVE-2026-10536
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
CVE-2026-10536
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
CVE-2026-10536
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
CVE-2026-10536
HTTP/2 stream-dependency tree UAF
CVE-2026-10536
A use-after-free vulnerability exists in libcurl when an application c ...
GHSA-wjq8-x4qm-6mmh
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
BDU:2026-08696
Уязвимость механизма управления деревом зависимостей потоков протокола HTTP/2 библиотеки libcurl программного средства для взаимодействия с серверами cURL, позволяющая нарушителю вызвать отказ в обслуживании
openSUSE-SU-2026:21272-1
Security update for curl
SUSE-SU-2026:3043-1
Security update for curl
SUSE-SU-2026:2926-1
Security update for curl
SUSE-SU-2026:2925-1
Security update for curl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-10536 A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. | CVSS3: 9.8 | 1% Низкий | около 1 месяца назад | |
CVE-2026-10536 A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. | CVSS3: 4.7 | 1% Низкий | около 1 месяца назад | |
CVE-2026-10536 A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. | CVSS3: 9.8 | 1% Низкий | около 1 месяца назад | |
CVE-2026-10536 HTTP/2 stream-dependency tree UAF | CVSS3: 4.7 | 1% Низкий | 27 дней назад | |
CVE-2026-10536 A use-after-free vulnerability exists in libcurl when an application c ... | CVSS3: 9.8 | 1% Низкий | около 1 месяца назад | |
GHSA-wjq8-x4qm-6mmh A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. | CVSS3: 9.8 | 1% Низкий | около 1 месяца назад | |
BDU:2026-08696 Уязвимость механизма управления деревом зависимостей потоков протокола HTTP/2 библиотеки libcurl программного средства для взаимодействия с серверами cURL, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 3.7 | 1% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21272-1 Security update for curl | 28 дней назад | |||
SUSE-SU-2026:3043-1 Security update for curl | 21 день назад | |||
SUSE-SU-2026:2926-1 Security update for curl | 22 дня назад | |||
SUSE-SU-2026:2925-1 Security update for curl | 22 дня назад |
Уязвимостей на страницу