CVE-2026-3805
HIGHcurl - Use After Free
Title source: llmDescription
When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
Exploits (1)
Scores
CVSS v3
7.5
EPSS
0.0003
EPSS Percentile
8.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (1)
haxx/curl
8.13.0 - 8.19.0
Published
Mar 11, 2026
Tracked Since
Mar 11, 2026