Количество 13
Количество 13
CVE-2026-10536
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
CVE-2026-10536
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
CVE-2026-10536
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
CVE-2026-10536
HTTP/2 stream-dependency tree UAF
CVE-2026-10536
A use-after-free vulnerability exists in libcurl when an application c ...
GHSA-wjq8-x4qm-6mmh
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
BDU:2026-08696
Уязвимость механизма управления деревом зависимостей потоков протокола HTTP/2 библиотеки libcurl программного средства для взаимодействия с серверами cURL, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260921-80-0047
Уязвимость curl
SUSE-SU-2026:3814-1
Security update for curl
openSUSE-SU-2026:21272-1
Security update for curl
SUSE-SU-2026:3043-1
Security update for curl
SUSE-SU-2026:2926-1
Security update for curl
SUSE-SU-2026:2925-1
Security update for curl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-10536 A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-10536 A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. | CVSS3: 4.7 | 1% Низкий | 3 месяца назад | |
CVE-2026-10536 A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-10536 HTTP/2 stream-dependency tree UAF | CVSS3: 4.7 | 1% Низкий | 3 месяца назад | |
CVE-2026-10536 A use-after-free vulnerability exists in libcurl when an application c ... | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
GHSA-wjq8-x4qm-6mmh A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
BDU:2026-08696 Уязвимость механизма управления деревом зависимостей потоков протокола HTTP/2 библиотеки libcurl программного средства для взаимодействия с серверами cURL, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 3.7 | 1% Низкий | 4 месяца назад | |
ROS-20260921-80-0047 Уязвимость curl | CVSS3: 3.7 | 1% Низкий | 4 дня назад | |
SUSE-SU-2026:3814-1 Security update for curl | 30 дней назад | |||
openSUSE-SU-2026:21272-1 Security update for curl | 3 месяца назад | |||
SUSE-SU-2026:3043-1 Security update for curl | 2 месяца назад | |||
SUSE-SU-2026:2926-1 Security update for curl | 2 месяца назад | |||
SUSE-SU-2026:2925-1 Security update for curl | 2 месяца назад |
Уязвимостей на страницу