{"id":"CVE-2026-18924","title":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.","summary":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-416","CWE-825"],"vendor":"haxx","product":"curl","affected":["curl >= 7.44.0, < 8.22.0"],"patched":["curl 8.22.0"],"published":"2026-09-06","updated":"2026-09-15","sourceUpdated":"2026-09-15T07:16:27.063","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","references":[{"url":"https://curl.se/docs/CVE-2026-18924.html","label":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"url":"https://curl.se/docs/CVE-2026-18924.json","label":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"url":"https://hackerone.com/reports/3916059","label":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"url":"https://hackerone.com/reports/3916059","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18924.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-18924"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2529201"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-18924"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924"},{"url":"https://access.redhat.com/errata/RHSA-2026:63514"},{"url":"https://access.redhat.com/errata/RHSA-2026:63161"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat","score-dispute"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-08T15:40:47.638991Z"},"epss":0.00897,"epssPercentile":0.57559,"ingestedAt":"2026-09-07T09:08:15.522Z","scores":{"nvd":9.1,"vendor":3.7},"slug":"CVE-2026-18924","body":"## Overview\n\nA flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.\n\n## Affected\n\n- `curl >= 7.44.0, < 8.22.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `curl 8.22.0`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4, … · no fix planned: Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18924.json)\n- **RHSA-2026:63514** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:63514)\n- **RHSA-2026:63161** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63161)","depth":"abyssal","depthScore":62,"depthScoreParts":{"impact":50.1,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":4982,"id":"CVE-2026-18924","ts":1788887223849,"field":"exploit_available","old":"false","new":"true"},{"seq":4981,"id":"CVE-2026-18924","ts":1788887223849,"field":"cvss","old":null,"new":"9.1"},{"seq":4980,"id":"CVE-2026-18924","ts":1788887223849,"field":"severity","old":"none","new":"critical"},{"seq":3865,"id":"CVE-2026-18924","ts":1788886355710,"field":"exploit_available","old":"true","new":"false"},{"seq":3864,"id":"CVE-2026-18924","ts":1788886355710,"field":"cvss","old":"9.1","new":null},{"seq":3863,"id":"CVE-2026-18924","ts":1788886355710,"field":"severity","old":"critical","new":"none"},{"seq":3291,"id":"CVE-2026-18924","ts":1788885294180,"field":"exploit_available","old":"false","new":"true"},{"seq":3290,"id":"CVE-2026-18924","ts":1788885294180,"field":"cvss","old":null,"new":"9.1"},{"seq":3289,"id":"CVE-2026-18924","ts":1788885294180,"field":"severity","old":"none","new":"critical"}]}