Skip to main content
QUIETLYTIC
Vulnerability

curl Use-After-Free (CVE-2026-80229)

CVE-2026-80229 is a CVSS 7.5 high-severity use-after-free in libcurl's OpenSSL 3 provider integration when a pooled TLS connection outlives the easy handle that created it.

CVE-2026-80229
Threat Level
HIGH
CVSS
7.5
Status
Monitored
Confidence
Medium
Affected Products
curl, libcurl

CVE-2026-80229 is a high-severity (CVSS 3.1 base 7.5) use-after-free vulnerability in libcurl’s multi-interface transfer handling, specific to OpenSSL 3 provider configurations.

What the vulnerability does

Per curl’s own advisory, when performing transfers via libcurl’s multi interface, pooled TLS connections can outlive the “easy handle” that originally created them — a normal part of how libcurl reuses connections for efficiency. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle’s own state and hands it to OpenSSL without acquiring a proper ownership reference. If that easy handle is destroyed prematurely while the pooled connection is still active, the context gets freed while the connection retains a dangling pointer to it — a use-after-free triggered on subsequent I/O or post-handshake operations.

The CVSS vector reflects a network-reachable, low-complexity flaw needing no authentication or user interaction, with an integrity/availability impact consistent with memory corruption in a library used across an enormous span of software.

What we don’t yet have

This record traces to curl’s own advisory and a HackerOne report via NVD; no CISA KEV listing or independent second-source corroboration is present, so confidence is medium.

Why this matters

This specifically affects applications using libcurl’s multi interface with connection sharing/pooling on OpenSSL 3 — a pattern common in high-throughput services making many concurrent HTTP requests. Given libcurl’s ubiquity as an embedded HTTP client, any application matching this configuration should confirm its libcurl version against curl’s fix.

Frequently Asked Questions

What is CVE-2026-80229? A CVSS 7.5 high-severity use-after-free in libcurl, occurring when an easy handle is destroyed while its pooled TLS connection (under OpenSSL 3) is still active.

Is CVE-2026-80229 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 curl.se

Related intelligence


Analyst tools