Skip to main content
QUIETLYTIC
Vulnerability

curl Vulnerability (CVE-2026-18924)

CVE-2026-18924 is a CVSS 9.1 critical use-after-free in libcurl's HTTP/2 Server Push handling when a handle shares connections with other handles.

CVE-2026-18924
Threat Level
CRITICAL
CVSS
9.1
Status
Monitored
Confidence
Medium
Affected Products
curl, libcurl

CVE-2026-18924 is a critical (CVSS 3.1 base 9.1) use-after-free vulnerability in libcurl’s handling of HTTP/2 Server Push. Like CVE-2026-19931 and CVE-2026-13608, this is a curl/libcurl vulnerability that also appears in Microsoft’s own security-update data because Windows bundles libcurl — the affected project is curl, not Microsoft-authored code.

What the vulnerability does

Per curl’s own advisory, the flaw occurs in libcurl’s cleanup process for HTTP/2 Server Push streams specifically when the parent transfer handle is configured to share connections with other handles (CURLOPT_SHARE/connection-sharing setups). Under this condition, cleanup can free memory that a subsequent operation still references, producing a use-after-free.

The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) indicates a network-reachable, low-complexity flaw needing no authentication or user interaction, with high impact to integrity and availability — a use-after-free of this kind can typically be leveraged for a crash (denial of service) and, depending on heap layout, potentially further memory corruption.

What we don’t yet have

No public proof-of-concept or evidence of active exploitation is documented as of this writing, and CVE-2026-18924 is not listed in CISA’s KEV catalog. Confidence is medium — the description and CVSS trace to NVD/curl’s advisory, but our ingested data doesn’t yet carry the specific affected/fixed version range; consult curl’s own advisory for exact version boundaries.

Why this matters

Applications that enable HTTP/2 Server Push and share libcurl handles/connections across transfers are the ones actually exposed here — a narrower blast radius than a default single-handle libcurl usage, but still a real memory-safety bug in a library embedded across an enormous range of software (from CLI tools to language runtimes’ HTTP clients). Teams using connection-sharing with Server Push enabled should prioritize confirming their libcurl version against curl’s fix once identified.

Frequently Asked Questions

What is CVE-2026-18924? A CVSS 9.1 critical use-after-free in libcurl, triggered during HTTP/2 Server Push stream cleanup when connections are shared across handles.

Is this a Microsoft vulnerability? No — it’s a libcurl (curl project) vulnerability that appears in Microsoft’s data because Windows bundles libcurl.

Is CVE-2026-18924 being actively exploited? Not as of this writing — it is not listed in CISA’s Known Exploited Vulnerabilities catalog.


Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 curl.se

Related intelligence


Analyst tools