CVE-2026-9080
ANALYSIS PENDINGcurl - UAF After Pause in Socket Callback
Title source: ruleDescription
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.
References (3)
Core 3
Core References
Scores
EPSS
0.0021
EPSS Percentile
10.8%
Details
Status
published
Products (9)
curl/curl
8.13.0
curl/curl
8.14.0
curl/curl
8.14.1
curl/curl
8.15.0
curl/curl
8.16.0
curl/curl
8.17.0
curl/curl
8.18.0
curl/curl
8.19.0
curl/curl
8.20.0
Published
Jul 03, 2026
Tracked Since
Jul 03, 2026