CVE-2026-18924 is a critical (CVSS 3.1 base 9.1) use-after-free vulnerability in libcurl’s handling of HTTP/2 Server Push. Like CVE-2026-19931 and CVE-2026-13608, this is a curl/libcurl vulnerability that also appears in Microsoft’s own security-update data because Windows bundles libcurl — the affected project is curl, not Microsoft-authored code.
What the vulnerability does
Per curl’s own advisory, the flaw occurs in libcurl’s cleanup process for HTTP/2 Server Push streams specifically when the parent transfer handle is configured to share connections with other handles (CURLOPT_SHARE/connection-sharing setups). Under this condition, cleanup can free memory that a subsequent operation still references, producing a use-after-free.
The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) indicates a network-reachable, low-complexity flaw needing no authentication or user interaction, with high impact to integrity and availability — a use-after-free of this kind can typically be leveraged for a crash (denial of service) and, depending on heap layout, potentially further memory corruption.
What we don’t yet have
No public proof-of-concept or evidence of active exploitation is documented as of this writing, and CVE-2026-18924 is not listed in CISA’s KEV catalog. Confidence is medium — the description and CVSS trace to NVD/curl’s advisory, but our ingested data doesn’t yet carry the specific affected/fixed version range; consult curl’s own advisory for exact version boundaries.
Why this matters
Applications that enable HTTP/2 Server Push and share libcurl handles/connections across transfers are the ones actually exposed here — a narrower blast radius than a default single-handle libcurl usage, but still a real memory-safety bug in a library embedded across an enormous range of software (from CLI tools to language runtimes’ HTTP clients). Teams using connection-sharing with Server Push enabled should prioritize confirming their libcurl version against curl’s fix once identified.
Frequently Asked Questions
What is CVE-2026-18924? A CVSS 9.1 critical use-after-free in libcurl, triggered during HTTP/2 Server Push stream cleanup when connections are shared across handles.
Is this a Microsoft vulnerability? No — it’s a libcurl (curl project) vulnerability that appears in Microsoft’s data because Windows bundles libcurl.
Is CVE-2026-18924 being actively exploited? Not as of this writing — it is not listed in CISA’s Known Exploited Vulnerabilities catalog.
Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.