VYPR
Critical severity9.8NVD Advisory· Published Jul 3, 2026· Updated Jul 7, 2026

CVE-2026-10536

CVE-2026-10536

Description

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via CURLOPT_STREAM_DEPENDS or CURLOPT_STREAM_DEPENDS_E, subsequently invokes curl_easy_reset(), and finally terminates the handle with curl_easy_cleanup(). During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

Affected products

14

Patches

Vulnerability mechanics

References

3

News mentions

2