Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-18924: curl can crash or be exploited via HTTP/2 server push
CVE-2026-18924 · published 21 days ago
Summary
The curl command‑line tool and libraries that use libcurl may mishandle HTTP/2 server‑push data when they are set to share connections between multiple tasks. This mistake can free memory too soon, causing the program to crash or potentially allow an attacker to run code. Update curl to the latest version provided by your vendor to resolve the issue.
What to do
- Update bellsoft curl to version 8.22.0-r0.
- Update curl to version 8.22.0-r0.
- Update curl to version 8.14.1-2+deb13u5.aikido.19.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.19.
- Update curl to version 8.14.1-r200711.
- Update rootio-curl to version 8.14.1-r200711.
- Update curl to version 8.14.1-r30077.
- Update rootio-curl to version 8.14.1-r30077.
- Update curl to version 8.5.0-r00073.
- Update rootio-curl to version 8.5.0-r00073.
- Update curl to version 8.14.1-r20075.
- Update rootio-curl to version 8.14.1-r20075.
- Update debian curl to version 8.22.0~rc2-1.
- Update curl to version 8.14.1-2+deb13u5.aikido.20.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.20.
- Update haxx curl to version 8.22.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | curl | curl |
<= 8.21.0 < 8.14.2 < 90325ff0444cbdff368bda5d26d6405a0bb6ee43 8.21.0 |
| Ubuntu:Pro:14.04:LTS | canonical | curl | All versions |
| Alpaquita:23 | bellsoft | curl |
>= 8.1.0-r2, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| Alpaquita:25 | bellsoft | curl |
>= 8.14.0-r1, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| Alpaquita:stream | bellsoft | curl |
>= 8.1.2-r0, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| BellSoft Hardened Containers:stream | bellsoft | curl |
>= 8.1.2-r0, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| Debian:12 | debian | curl | All versions |
| BellSoft Hardened Containers:stream | – | curl |
>= 8.1.2-r0, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| – | haxx | curl |
>= 7.44.0, < 8.22.0 cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* |
| Alpine:v3.23 | – | curl |
>= 7.44.0, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| Root:Debian:13 | – | curl |
< 8.14.1-2+deb13u5.aikido.19 < 8.14.1-2+deb13u5.aikido.20 Fix: upgrade to 8.14.1-2+deb13u5.aikido.19
|
| Root:Debian:13 | – | rootio-curl |
< 8.14.1-2+deb13u5.aikido.19 < 8.14.1-2+deb13u5.aikido.20 Fix: upgrade to 8.14.1-2+deb13u5.aikido.19
|
| Root:Alpine:3.20 | – | curl |
< 8.14.1-r200711 Fix: upgrade to 8.14.1-r200711
|
| Root:Alpine:3.20 | – | rootio-curl |
< 8.14.1-r200711 Fix: upgrade to 8.14.1-r200711
|
| Root:Alpine:3.22 | – | curl |
< 8.14.1-r30077 Fix: upgrade to 8.14.1-r30077
|
| Root:Alpine:3.22 | – | rootio-curl |
< 8.14.1-r30077 Fix: upgrade to 8.14.1-r30077
|
| Root:Alpine:3.15 | – | curl |
< 8.5.0-r00073 Fix: upgrade to 8.5.0-r00073
|
| Root:Alpine:3.15 | – | rootio-curl |
< 8.5.0-r00073 Fix: upgrade to 8.5.0-r00073
|
| Root:Alpine:3.21 | – | curl |
< 8.14.1-r20075 Fix: upgrade to 8.14.1-r20075
|
| Root:Alpine:3.21 | – | rootio-curl |
< 8.14.1-r20075 Fix: upgrade to 8.14.1-r20075
|
| Debian:14 | debian | curl |
< 8.22.0~rc2-1 Fix: upgrade to 8.22.0~rc2-1
|
Original advisory text
HTTP/2 server push UAF
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.
References
- https://ubuntu.com/security/CVE-2026-18924 Third Party Advisory
- https://docs.bell-sw.com/security/cves/CVE-2026-18924 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-18924 Vendor Advisory
- https://curl.se/docs/CVE-2026-18924.json URL
- https://hackerone.com/reports/3916059 URL
- https://github.com/curl/curl.git Product
- https://curl.se/docs/CVE-2026-18924.html Third Party Advisory
- https://security.alpinelinux.org/vuln/CVE-2026-18924 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18924... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-18924 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-18924 Third Party Advisory
- https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6 Third Party Advisory
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published6 Sep 2026
Updated27 Sep 2026
First seen2 Sep 2026
Sources
CURL-CVE-2026-18924 · OSV
CVE-2026-18924 · NVD
UBUNTU-CVE-2026-18924 · OSV
BELL-CVE-2026-18924 · OSV
CVE-2026-18924 · MITRE
DEBIAN-CVE-2026-18924 · OSV
ALPINE-CVE-2026-18924 · OSV
CVE-2026-18924 · OSV
Track software like this
Free during beta