CVE-2026-18924
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://curl.se/docs/CVE-2026-18924.html, https://curl.se/docs/CVE-2026-18924.json, https://hackerone.com/reports/3916059, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18924.json, https://nvd.nist.gov/vuln/detail/CVE-2026-18924, https://github.com/curl/curl.git