SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-18924

CRITICAL · CVSS 9.1 EPSS 0.90%

Source: NVD + CISA KEV + EPSS · Published 2026-09-06 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A vulnerability in libcurl affects its handling of HTTP/2 Server Push streams when connection sharing is enabled, potentially leading to a use-after-free condition during cleanup. This flaw could allow an attacker to exploit memory management issues, resulting in application crashes or arbitrary code execution. Developers and organizations utilizing libcurl in their applications should prioritize this issue to mitigate potential security risks.

CVE
CVE-2026-18924
Severity
CRITICAL
CVSS
9.1
EPSS
0.90%

Original NVD Description

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

Related CVEs

Other vulnerabilities affecting the same vendor(s)