CVE-2021-22901High· 8.1▾ Twilightcurl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstance…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 12 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
60%
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL, it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection) that first transfer object might be freed before the new session is established on that connection and then the function will access a memory buffer that might be freed. When using that memory, libcurl might even call a function pointer in the object, making it possible for a remote code execution if the server could somehow manage to get crafted memory content into the correct place in memory.
curl >= 7.75.0, <= 7.76.1communications_cloud_native_core_binding_support_function = 1.11.0communications_cloud_native_core_network_function_cloud_native_environment = 1.10.0communications_cloud_native_core_network_repository_function = 1.15.0communications_cloud_native_core_network_repository_function = 1.15.1communications_cloud_native_core_network_slice_selection_function = 1.8.0communications_cloud_native_core_service_communication_proxy = 1.15.0essbase < 11.1.2.4.047essbase >= 21.0, < 21.3mysql_server <= 5.7.34mysql_server >= 8.0.0, <= 8.0.25active_iq_unified_managercloud_backuponcommand_insightoncommand_workflow_automationsnapcentersolidfire,_enterprise_sds_&_hci_storage_nodesolidfire_&_hci_management_nodesolidfire_baseboard_management_controller_firmwarehci_compute_node_firmwareh300e_firmwareh300s_firmwareh410s_firmwareh500e_firmwareh500s_firmwareh700e_firmwareh700s_firmwaresinec_infrastructure_network_services < 1.0.1.1universal_forwarder >= 8.2.0, < 8.2.12universal_forwarder >= 9.0.0, < 9.0.6universal_forwarder = 9.1.0Upgrade past the affected range:
essbase 21.3sinec_infrastructure_network_services 1.0.1.1universal_forwarder 9.0.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-3805High· 7.5When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
CVE-2026-80229High· 7.5When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles
CVE-2026-18924Critical· 9.1A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.
CVE-2026-9080High· 7.3Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory…
CVE-2026-10536Critical· 9.8A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates…
CVE-2022-27778High· 8.1A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.