Use-After-Free in libcurl during cleanup after stream-dependency reset
CVE-2026-10536 Published on July 3, 2026
HTTP/2 stream-dependency tree UAF
A use-after-free vulnerability exists in libcurl when an application
configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or
`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and
finally terminates the handle with `curl_easy_cleanup()`. During this final
cleanup phase, libcurl attempts to access and modify an internal structure
that was already freed during the reset operation.
Vulnerability Analysis
CVE-2026-10536 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. An automatable proof of concept (POC) exploit exists. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
What is a Dangling pointer Vulnerability?
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
CVE-2026-10536 has been classified to as a Dangling pointer vulnerability or weakness.
Products Associated with CVE-2026-10536
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-10536 are published in these products:
Affected Versions
curl:- Version 7.88.0 and below 8.14.2 is affected.
- Version 8.15.0 and below 8.16.1 is affected.
- Version 8.17.0 and below 8.20.1 is affected.
- Version 71b7e0161032927cdfb4e75ea40f65b8898b3956 and below bfbff7852f050232edd3e5ca5c6bf2021c340f5a is affected.
- Version 8.20.0 is affected.
- Version 8.19.0 is affected.
- Version 8.18.0 is affected.
- Version 8.17.0 is affected.
- Version 8.16.0 is affected.
- Version 8.15.0 is affected.
- Version 8.14.1 is affected.
- Version 8.14.0 is affected.
- Version 8.13.0 is affected.
- Version 8.12.1 is affected.
- Version 8.12.0 is affected.
- Version 8.11.1 is affected.
- Version 8.11.0 is affected.
- Version 8.10.1 is affected.
- Version 8.10.0 is affected.
- Version 8.9.1 is affected.
- Version 8.9.0 is affected.
- Version 8.8.0 is affected.
- Version 8.7.1 is affected.
- Version 8.7.0 is affected.
- Version 8.6.0 is affected.
- Version 8.5.0 is affected.
- Version 8.4.0 is affected.
- Version 8.3.0 is affected.
- Version 8.2.1 is affected.
- Version 8.2.0 is affected.
- Version 8.1.2 is affected.
- Version 8.1.1 is affected.
- Version 8.1.0 is affected.
- Version 8.0.1 is affected.
- Version 8.0.0 is affected.
- Version 7.88.1 is affected.
- Version 7.88.0 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.