CVE-2026-8925
The curl logic that works with SASL authentication could end up cleaning up
the GSASL context twice without clearing the pointer in between, making it
free() the same pointer twice.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://curl.se/docs/CVE-2026-8925.html, https://curl.se/docs/CVE-2026-8925.json, https://hackerone.com/reports/3735193, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8925.json, https://nvd.nist.gov/vuln/detail/CVE-2026-8925