CVE-2026-10536
A use-after-free vulnerability exists in libcurl when an application
configures an HTTP/2 stream-dependency tree via CURLOPTSTREAMDEPENDS or
CURLOPTSTREAMDEPENDS_E, subsequently invokes curleasyreset(), and
finally terminates the handle with curleasycleanup(). During this final
cleanup phase, libcurl attempts to access and modify an internal structure
that was already freed during the reset operation.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://curl.se/docs/CVE-2026-10536.html, https://curl.se/docs/CVE-2026-10536.json, https://hackerone.com/reports/3751697, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10536.json, https://nvd.nist.gov/vuln/detail/CVE-2026-10536