---
id: CVE-2026-18924
title: |-
  A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
  handle is set to share connections with other handles, can lead to
  use-after-free in the cleanup process.
summary: |-
  A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
  handle is set to share connections with other handles, can lead to
  use-after-free in the cleanup process.
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-416
  - CWE-825
vendor: haxx
product: curl
affected:
  - 'curl >= 7.44.0, < 8.22.0'
patched:
  - curl 8.22.0
published: '2026-09-06'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T07:16:27.063'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18924'
references:
  - url: 'https://curl.se/docs/CVE-2026-18924.html'
    label: 2499f714-1537-4658-8207-48ae4bb9eae9
  - url: 'https://curl.se/docs/CVE-2026-18924.json'
    label: 2499f714-1537-4658-8207-48ae4bb9eae9
  - url: 'https://hackerone.com/reports/3916059'
    label: 2499f714-1537-4658-8207-48ae4bb9eae9
  - url: 'https://hackerone.com/reports/3916059'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18924.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-18924'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2529201'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-18924'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18924'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63514'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63161'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
  - score-dispute
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T15:40:47.638991Z'
epss: 0.00897
epssPercentile: 0.57559
ingestedAt: '2026-09-07T09:08:15.522Z'
scores:
  nvd: 9.1
  vendor: 3.7
---

## Overview

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.

## Affected

- `curl >= 7.44.0, < 8.22.0`

## Remediation

Upgrade past the affected range:

- `curl 8.22.0`

## Vendor advisories

- **Red Hat VEX** · Low · affected: Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4, … · no fix planned: Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18924.json)
- **RHSA-2026:63514** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:63514)
- **RHSA-2026:63161** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63161)
