Vulnerability in libcurl Affecting HTTP/2 Server Push Streams
CVE-2026-18924

Currently unrated

Key Information:

Vendor

Curl

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-18924?

A serious flaw exists in libcurl's management of HTTP/2 Server Push streams. When the parent connection handle shares resources with other connections, a use-after-free condition may occur during the cleanup process. This can lead to unexpected behaviors or potential exploitation in applications using affected versions of libcurl. Proper attention to connection management is essential to mitigate risks associated with this vulnerability.

Affected Version(s)

curl 8.21.0

curl 8.20.0

curl 8.19.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stephan Zeisberg (Security Research Labs)
Daniel Stenberg
.