CVE
CURL-CVE-2026-10536
HTTP/2 stream-dependency tree UAF
A use-after-free vulnerability exists in libcurl when an application
configures an HTTP/2 stream-dependency tree via CURLOPTSTREAMDEPENDS or
CURLOPTSTREAMDEPENDS_E, subsequently invokes curleasyreset(), and
finally terminates the handle with curleasycleanup(). During this final
cleanup phase, libcurl attempts to access and modify an internal structure
that was already freed during the reset operation.
Package Versions Affected
Package Version
patch Availability
No items found.
Automatically patch vulnerabilities without upgrading
Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request
CVSS Version
Severity
Base Score
CVSS Version
Score Vector

C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

C
H
U
0
-

C
H
U
-
Related Resources
No items found.