Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-18924: curl can crash or be exploited via HTTP/2 server push

CVE-2026-18924 · published 21 days ago
Summary

The curl command‑line tool and libraries that use libcurl may mishandle HTTP/2 server‑push data when they are set to share connections between multiple tasks. This mistake can free memory too soon, causing the program to crash or potentially allow an attacker to run code. Update curl to the latest version provided by your vendor to resolve the issue.

What to do
  • Update bellsoft curl to version 8.22.0-r0.
  • Update curl to version 8.22.0-r0.
  • Update curl to version 8.14.1-2+deb13u5.aikido.19.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.19.
  • Update curl to version 8.14.1-r200711.
  • Update rootio-curl to version 8.14.1-r200711.
  • Update curl to version 8.14.1-r30077.
  • Update rootio-curl to version 8.14.1-r30077.
  • Update curl to version 8.5.0-r00073.
  • Update rootio-curl to version 8.5.0-r00073.
  • Update curl to version 8.14.1-r20075.
  • Update rootio-curl to version 8.14.1-r20075.
  • Update debian curl to version 8.22.0~rc2-1.
  • Update curl to version 8.14.1-2+deb13u5.aikido.20.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.20.
  • Update haxx curl to version 8.22.0 or later.
Affected software
Ecosystem VendorProductAffected versions
– curl curl <= 8.21.0
< 8.14.2
< 90325ff0444cbdff368bda5d26d6405a0bb6ee43
8.21.0
Ubuntu:Pro:14.04:LTS canonical curl All versions
Alpaquita:23 bellsoft curl >= 8.1.0-r2, < 8.22.0-r0
Fix: upgrade to 8.22.0-r0
Alpaquita:25 bellsoft curl >= 8.14.0-r1, < 8.22.0-r0
Fix: upgrade to 8.22.0-r0
Alpaquita:stream bellsoft curl >= 8.1.2-r0, < 8.22.0-r0
Fix: upgrade to 8.22.0-r0
BellSoft Hardened Containers:stream bellsoft curl >= 8.1.2-r0, < 8.22.0-r0
Fix: upgrade to 8.22.0-r0
Debian:12 debian curl All versions
BellSoft Hardened Containers:stream – curl >= 8.1.2-r0, < 8.22.0-r0
Fix: upgrade to 8.22.0-r0
– haxx curl >= 7.44.0, < 8.22.0
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
Alpine:v3.23 – curl >= 7.44.0, < 8.22.0-r0
Fix: upgrade to 8.22.0-r0
Root:Debian:13 – curl < 8.14.1-2+deb13u5.aikido.19
< 8.14.1-2+deb13u5.aikido.20
Fix: upgrade to 8.14.1-2+deb13u5.aikido.19
Root:Debian:13 – rootio-curl < 8.14.1-2+deb13u5.aikido.19
< 8.14.1-2+deb13u5.aikido.20
Fix: upgrade to 8.14.1-2+deb13u5.aikido.19
Root:Alpine:3.20 – curl < 8.14.1-r200711
Fix: upgrade to 8.14.1-r200711
Root:Alpine:3.20 – rootio-curl < 8.14.1-r200711
Fix: upgrade to 8.14.1-r200711
Root:Alpine:3.22 – curl < 8.14.1-r30077
Fix: upgrade to 8.14.1-r30077
Root:Alpine:3.22 – rootio-curl < 8.14.1-r30077
Fix: upgrade to 8.14.1-r30077
Root:Alpine:3.15 – curl < 8.5.0-r00073
Fix: upgrade to 8.5.0-r00073
Root:Alpine:3.15 – rootio-curl < 8.5.0-r00073
Fix: upgrade to 8.5.0-r00073
Root:Alpine:3.21 – curl < 8.14.1-r20075
Fix: upgrade to 8.14.1-r20075
Root:Alpine:3.21 – rootio-curl < 8.14.1-r20075
Fix: upgrade to 8.14.1-r20075
Debian:14 debian curl < 8.22.0~rc2-1
Fix: upgrade to 8.22.0~rc2-1
Original advisory text
HTTP/2 server push UAF
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published6 Sep 2026
Updated27 Sep 2026
First seen2 Sep 2026
Track software like this
Free during beta