← Back to CVE List
Vulnerability Intelligence Report
HTTP/2 stream-dependency tree UAF

CVE-2026-10536

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.89%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-416 ↗Use After Free

Affected Products & Versions

Vendor Product Affected Versions
curl curl 7.88.0 < 8.14.2 (affected), 8.15.0 < 8.16.1 (affected), 8.17.0 < 8.20.1 (affected)
curl curl 71b7e0161032927cdfb4e75ea40f65b8898b3956 < bfbff7852f050232edd3e5ca5c6bf2021c340f5a (affected)
curl curl 8.20.0 (affected), 8.19.0 (affected), 8.18.0 (affected), 8.17.0 (affected), 8.16.0 (affected), 8.15.0 (affected), 8.14.1 (affected), 8.14.0 (affected), 8.13.0 (affected), 8.12.1 (affected), 8.12.0 (affected), 8.11.1 (affected), 8.11.0 (affected), 8.10.1 (affected), 8.10.0 (affected), 8.9.1 (affected), 8.9.0 (affected), 8.8.0 (affected), 8.7.1 (affected), 8.7.0 (affected), 8.6.0 (affected), 8.5.0 (affected), 8.4.0 (affected), 8.3.0 (affected), 8.2.1 (affected), 8.2.0 (affected), 8.1.2 (affected), 8.1.1 (affected), 8.1.0 (affected), 8.0.1 (affected), 8.0.0 (affected), 7.88.1 (affected), 7.88.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.891%

Identity & Timeline

StatusPUBLISHED
Assigning Authoritycurl · Open Source · Sweden
Reserved2026-06-01T11:49:55
Published2026-07-03T06:11:15
Last Updated2026-09-15T06:02:36

LINK COPIED TO CLIPBOARD