Vulnerability Intelligence Report
HTTP/2 stream-dependency tree UAF
CVE-2026-10536
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.89%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-416 ↗Use After Free
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| curl | curl | 7.88.0 < 8.14.2 (affected), 8.15.0 < 8.16.1 (affected), 8.17.0 < 8.20.1 (affected) |
| curl | curl | 71b7e0161032927cdfb4e75ea40f65b8898b3956 < bfbff7852f050232edd3e5ca5c6bf2021c340f5a (affected) |
| curl | curl | 8.20.0 (affected), 8.19.0 (affected), 8.18.0 (affected), 8.17.0 (affected), 8.16.0 (affected), 8.15.0 (affected), 8.14.1 (affected), 8.14.0 (affected), 8.13.0 (affected), 8.12.1 (affected), 8.12.0 (affected), 8.11.1 (affected), 8.11.0 (affected), 8.10.1 (affected), 8.10.0 (affected), 8.9.1 (affected), 8.9.0 (affected), 8.8.0 (affected), 8.7.1 (affected), 8.7.0 (affected), 8.6.0 (affected), 8.5.0 (affected), 8.4.0 (affected), 8.3.0 (affected), 8.2.1 (affected), 8.2.0 (affected), 8.1.2 (affected), 8.1.1 (affected), 8.1.0 (affected), 8.0.1 (affected), 8.0.0 (affected), 7.88.1 (affected), 7.88.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.891%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | curl · Open Source · Sweden |
| Reserved | 2026-06-01T11:49:55 |
| Published | 2026-07-03T06:11:15 |
| Last Updated | 2026-09-15T06:02:36 |
Community Chatter & Buzz